Institutional-Repository, University of Moratuwa.  

Enhanced cloud security and compliance reference model for emerging SAAS cloud systems consuming public cloud services

Show simple item record

dc.contributor.advisor Fernando S
dc.contributor.author Fernando PRN
dc.date.accessioned 2022
dc.date.available 2022
dc.date.issued 2022
dc.identifier.citation Fernando, P.R.N. (2022). Enhanced cloud security and compliance reference model for emerging SAAS cloud systems consuming public cloud services [Master's theses, University of Moratuwa]. Institutional Repository University of Moratuwa. http://dl.lib.uom.lk/handle/123/21848
dc.identifier.uri http://dl.lib.uom.lk/handle/123/21848
dc.description.abstract Most businesses in operation at present have an online presence. This ranges from an ECommerce application to a business that offers NoSQL database capabilities as a service to its customers. With the inception of cloud computing, consumers started aligning with a service model to obtain cloud computing services. Cloud computing service models fall under three main categories: Infrastructure as a Service (IaaS), Platform as a Service (PaaS) and Software as a Service (SaaS). Many businesses, especially technologically driven startups, emerge by leveraging cloud service models. Most of those emerging businesses started to offer their services as a Software as a Service model. The growth of this trend has brought up new challenges for emerging startup businesses in managing the security, compliance and privacy of their services. Compliance and privacy have been popular among cloud consumers, cloud service providers, and governments worldwide. Governments have already started taking continuous initiatives to ensure the cloud-based software services comply with the standards, and the users’ privacy is guaranteed in the cloud services offered. These regulations are compulsory for a cloud business to exist in most places. If this is addressed from the perspective of an emerging SaaS business, keeping up with rapidly changing complex compliance standards and privacy regulations while making the cloud services secure has been a difficult task. This research mainly focuses on identifying methods for creating a threat model for SaaS cloud systems and determining how cloud security and compliance make a SaaS cloud system consuming public cloud services secure and compliant. Based on that, the research proposes an enhanced reference model that consists of patterns and best practices for designing and implementing a safe, compliant SaaS cloud system. Mapping of major categories within that reference model with existing cloud security and compliance standards was also carried out to make the proposed model more relatable to the real world. An implementation phase was conducted to showcase how this proposed model can be successfully applied to the real world. This included two major components: a machine learning model and an API service. The implemented API service allows users to retrieve insights and recommendations about their SaaS system security and compliance status by responding to audit questions. The insights and recommendations were generated based on clusters identified via the implemented machine learning models. The data required to develop the machine learning model were gathered by conducting an open survey among IT professionals working or with experience working at cloud-based software solutions offering companies in Sri Lanka, the majority being startups. This overall process paved the way for answering the research objectives while creating a solid implementation that enabled continuous and active evolvement of the proposed reference model. en_US
dc.language.iso en en_US
dc.subject CLOUD COMPUTING, , , , en_US
dc.subject SAAS CLOUD SYSTEMS en_US
dc.subject EMERGING CLOUD BUSINESSES en_US
dc.subject CLOUD SECURITY en_US
dc.subject CLOUD COMPLIANCE en_US
dc.subject INFORMATION TECHNOLOGY -Dissertation en_US
dc.subject COMPUTER SCIENCE -Dissertation en_US
dc.subject COMPUTER SCIENCE & ENGINEERING -Dissertation en_US
dc.title Enhanced cloud security and compliance reference model for emerging SAAS cloud systems consuming public cloud services en_US
dc.type Thesis-Abstract en_US
dc.identifier.faculty Engineering en_US
dc.identifier.degree MSc In Computer Science and Engineering en_US
dc.identifier.department Department of Computer Science and Engineering en_US
dc.date.accept 2022
dc.identifier.accno TH4939 en_US


Files in this item

This item appears in the following Collection(s)

Show simple item record