{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T14:59:46Z","timestamp":1784905186631,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":47,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,6,18]],"date-time":"2024-06-18T00:00:00Z","timestamp":1718668800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"MUR","award":["2020W3A5FY, PE00000014"],"award-info":[{"award-number":["2020W3A5FY, PE00000014"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,6,18]]},"DOI":"10.1145\/3661167.3661287","type":"proceedings-article","created":{"date-parts":[[2024,6,14]],"date-time":"2024-06-14T12:24:25Z","timestamp":1718367865000},"page":"604-613","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":12,"title":["Security Risk Assessment on Cloud: A Systematic Mapping Study"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-0742-7261","authenticated-orcid":false,"given":"Giusy","family":"Annunziata","sequence":"first","affiliation":[{"name":"Computer Science, University of Salerno, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-9734-3645","authenticated-orcid":false,"given":"Alexandra","family":"Sheykina","sequence":"additional","affiliation":[{"name":"Computer Science, University of Salerno, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9337-5116","authenticated-orcid":false,"given":"Fabio","family":"Palomba","sequence":"additional","affiliation":[{"name":"Computer Science, University of Salerno, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4238-1425","authenticated-orcid":false,"given":"Andrea","family":"De Lucia","sequence":"additional","affiliation":[{"name":"Computer Science, University of Salerno, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4689-3401","authenticated-orcid":false,"given":"Gemma","family":"Catolino","sequence":"additional","affiliation":[{"name":"Computer Science, University of Salerno, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0975-8972","authenticated-orcid":false,"given":"Filomena","family":"Ferrucci","sequence":"additional","affiliation":[{"name":"Computer Science, University of Salerno, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,6,18]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"ISO\/IEC 27017:2015. 2021. Code of practice for information security controls based on ISO\/IEC 27002 for cloud services. https:\/\/www.iso.org\/standard\/82878.html"},{"key":"e_1_3_2_1_2_1","unstructured":"ISO\/IEC\/IEEE 29119. 2021. Risk-based approach for testing. https:\/\/www.iso.org\/obp\/ui\/#iso:std:iso-iec-ieee:29119:-2:ed-2:v1:en"},{"key":"e_1_3_2_1_3_1","unstructured":"NIST\u00a0SP 800-144. 2011. Guidelines on Security and Privacy in Public Cloud Computing. https:\/\/csrc.nist.gov\/pubs\/sp\/800\/144\/final"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.14257\/ijgdc.2015.8.2.15"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/2652524.2652557"},{"key":"e_1_3_2_1_6_1","unstructured":"Cloud\u00a0Security Alliance. 2022. Cloud Security Alliance\u2019s Top\u200c \u200cThreats\u200c \u200cto\u200c \u200cCloud\u200c \u200cComputing. https:\/\/cloudsecurityalliance.org\/press-releases\/2022\/06\/07\/cloud-security-alliance-s-top-threats-to-cloud-computing-pandemic-11-report-finds-traditional-cloud-security-issues-becoming-less-concerning"},{"key":"e_1_3_2_1_7_1","volume-title":"Journal of Physics: Conference Series, Vol.\u00a01018","author":"Amini Ahmad","year":"2004","unstructured":"Ahmad Amini and Norziana Jamil. 2018. A comprehensive review of existing risk assessment models in cloud computing. In Journal of Physics: Conference Series, Vol.\u00a01018. IOP Publishing, 012004."},{"key":"e_1_3_2_1_8_1","unstructured":"Giusy Annunziata Alexandra Sheykina Fabio Palomba Gemma Catolino Andrea De\u00a0Lucia and Filomena Ferrucci. 2024. Online Appendix \u2014 Security Risk Assessment on Cloud: A Systematic Mapping Study. https:\/\/figshare.com\/s\/8c8c3af5213182a94334"},{"key":"e_1_3_2_1_9_1","unstructured":"CheckPoint. 2022. Top Trends in Cloud Security. https:\/\/pages.checkpoint.com\/2022-cloud-security-report.html"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1007\/s13198-016-0525-0"},{"key":"e_1_3_2_1_11_1","volume-title":"Security and Data Storage Aspect in Cloud Computing. Vol.\u00a052","author":"Deshpande S","unstructured":"Prachi\u00a0S Deshpande, Subhash\u00a0C Sharma, and Sateesh\u00a0K Peddoju. 2019. Security and Data Storage Aspect in Cloud Computing. Vol.\u00a052. Springer."},{"key":"e_1_3_2_1_12_1","volume-title":"Gartner Forecasts Worldwide Public Cloud End-User Spending to Reach $679 Billion","year":"2024","unstructured":"Gartner. 2023. Gartner Forecasts Worldwide Public Cloud End-User Spending to Reach $679 Billion in 2024. https:\/\/www.collinsdictionary.com\/dictionary\/english\/language"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-45231-8_23"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-26416-5_2"},{"key":"e_1_3_2_1_15_1","volume-title":"Enterprises Can\u2019t Get Enough SSE as Revenue Rockets 38 Percent","author":"Dell\u2019Oro Group","year":"2022","unstructured":"Dell\u2019Oro Group. 2023. Enterprises Can\u2019t Get Enough SSE as Revenue Rockets 38 Percent in 2022, According to Dell\u2019Oro Group. https:\/\/www.delloro.com\/news\/enterprises-cant-get-enough-sse-as-revenue-rockets-38-percent-in-2022\/#:\u00a0:text=\u2013%20March%2015%2C%202023%20\u2013%20According, representing%2038%20percent%20growth%20as"},{"key":"e_1_3_2_1_16_1","unstructured":"Barbara Kitchenham Stuart Charters 2007. Guidelines for performing systematic literature reviews in software engineering."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40861-8_42"},{"key":"e_1_3_2_1_18_1","unstructured":"W. Lidwell K. Holden and J. Butler. 2010. Universal principles of design revised and updated: 125 ways to enhance usability influence perception increase appeal make better design decisions and teach through design. Rockport Pub."},{"key":"e_1_3_2_1_19_1","unstructured":"NIST. [n. d.]. General Access Control Guidance for Cloud Systems: NIST Publishes SP 800-210. https:\/\/csrc.nist.rip\/News\/2020\/nist-publishes-sp-800-210-ac-guidance-for-cloud"},{"key":"e_1_3_2_1_20_1","unstructured":"NIST. 2011. The NIST Definition of Cloud Computing. https:\/\/nvlpubs.nist.gov\/nistpubs\/legacy\/sp\/nistspecialpublication800-145.pdf"},{"key":"e_1_3_2_1_21_1","unstructured":"NIST. 2020. General Access Control Guidance for Cloud Systems. https:\/\/csrc.nist.rip\/publications\/detail\/sp\/800-210\/final"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.14236\/ewic\/EASE2008.8"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2015.03.007"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-26416-5"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-26416-5_1"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2011.23"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1002\/sec.923"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.5220\/0006294401200131"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.4067\/S0718-18762013000300005"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1108\/ICS-03-2021-0034"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-69035-3_38"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/SCC.2014.48"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2019.8802752"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.12700\/APH.17.5.2020.5.6"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1002\/cpe.6423"},{"key":"e_1_3_2_1_36_1","volume-title":"SpaCCS 2017, Guangzhou, China, December 12-15, 2017, Proceedings 10","author":"Jouini Mouna","year":"2017","unstructured":"Mouna Jouini and Latifa Ben\u00a0Arfa Rabai. 2017. A security risk management model for cloud computing systems: infrastructure as a service. In Security, Privacy, and Anonymity in Computation, Communication, and Storage: 10th International Conference, SpaCCS 2017, Guangzhou, China, December 12-15, 2017, Proceedings 10. Springer, 594\u2013608."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/CloudCom.2012.6427574"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-43722-0_42"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2018.10.008"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/QRS.2018.00049"},{"key":"e_1_3_2_1_41_1","article-title":"Threat-specific security risk evaluation in the cloud","volume":"9","author":"Nhlabatsi Armstrong","year":"2018","unstructured":"Armstrong Nhlabatsi, Jin\u00a0B Hong, Dong\u00a0Seong Kim, Rachael Fernandez, Alaa Hussein, Noora Fetais, and Khaled\u00a0M Khan. 2018. Threat-specific security risk evaluation in the cloud. IEEE Transactions on Cloud Computing 9, 2 (2018).","journal-title":"IEEE Transactions on Cloud Computing"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICIoT48696.2020.9089459"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/CLOUD.2010.22"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2020.102617"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.2174\/1874110X01610010210"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3007338"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1142\/S0218001423510126"}],"event":{"name":"EASE 2024: 28th International Conference on Evaluation and Assessment in Software Engineering","location":"Salerno Italy","acronym":"EASE 2024"},"container-title":["Proceedings of the 28th International Conference on Evaluation and Assessment in Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3661167.3661287","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3661167.3661287","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T11:17:10Z","timestamp":1755861430000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3661167.3661287"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,6,18]]},"references-count":47,"alternative-id":["10.1145\/3661167.3661287","10.1145\/3661167"],"URL":"https:\/\/doi.org\/10.1145\/3661167.3661287","relation":{},"subject":[],"published":{"date-parts":[[2024,6,18]]},"assertion":[{"value":"2024-06-18","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}