{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T13:46:30Z","timestamp":1762004790544,"version":"build-2065373602"},"reference-count":25,"publisher":"MDPI AG","issue":"1","license":[{"start":{"date-parts":[[2016,2,17]],"date-time":"2016-02-17T00:00:00Z","timestamp":1455667200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Individuals and corporate users are persistently considering cloud adoption due to its significant benefits compared to traditional computing environments. The data and applications in the cloud are stored in an environment that is separated, managed and maintained externally to the organisation. Therefore, it is essential for cloud providers to demonstrate and implement adequate security practices to protect the data and processes put under their stewardship. Security transparency in the cloud is likely to become the core theme that underpins the systematic disclosure of security designs and practices that enhance customer confidence in using cloud service and deployment models. In this paper, we present a framework that enables a detailed analysis of security transparency for cloud based systems. In particular, we consider security transparency from three different levels of abstraction, i.e., conceptual, organisation and technical levels, and identify the relevant concepts within these levels. This allows us to provide an elaboration of the essential concepts at the core of transparency and analyse the means for implementing them from a technical perspective. Finally, an example from a real world migration context is given to provide a solid discussion on the applicability of the proposed framework.<\/jats:p>","DOI":"10.3390\/fi8010005","type":"journal-article","created":{"date-parts":[[2016,2,18]],"date-time":"2016-02-18T22:19:47Z","timestamp":1455833987000},"page":"5","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":19,"title":["A Framework for Security Transparency in Cloud Computing"],"prefix":"10.3390","volume":"8","author":[{"given":"Umar","family":"Ismail","sequence":"first","affiliation":[{"name":"School of Architecture, Computing and Engineering, University of East London, London E162RD, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shareeful","family":"Islam","sequence":"additional","affiliation":[{"name":"School of Architecture, Computing and Engineering, University of East London, London E162RD, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Moussa","family":"Ouedraogo","sequence":"additional","affiliation":[{"name":"Luxembourg Institute of Science and Technology, L-4362 Esch-sur-Alzette, Luxembourg"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0665-6126","authenticated-orcid":false,"given":"Edgar","family":"Weippl","sequence":"additional","affiliation":[{"name":"Secure Business Austria, Sommerpalais Harrach, Favoritenstrasse 16, 1040 Wien, Austria"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2016,2,17]]},"reference":[{"key":"ref_1","first-page":"257","article-title":"The Security Risks Associated with Cloud Computing","volume":"1","author":"Agarwal","year":"2011","journal-title":"Int. J. Comput. Appl. Eng. Sci."},{"key":"ref_2","unstructured":"Islam, S., Ouedraogo, M., Kalloniatis, C., Mouratidis, H., and Gritzalis, S. (2015). Assurance of Security and Privacy Requirements for Cloud Deployment Model SI: Security and privacy protection on cloud. IEEE Trans. Cloud Comput."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Ouedraogo, M., and Shareeful, I. (2015, January 8\u201312). Towards the integration of Security Transparency in the Modelling and Design of Cloud Based Systems. Proceedings of the Advanced Information Systems Engineering Worships, Stockholm, Sweden.","DOI":"10.1007\/978-3-319-19243-7_45"},{"key":"ref_4","unstructured":"Rak, M., Casola, V., Beneditics, A., and Villano, U. (2014, January 3\u20135). Preliminary design of a platform-as-a-service to provide security in cloud. Proceedings of the 4th International Conference on Cloud Computing and Services Science, Barcelona, Spain."},{"key":"ref_5","unstructured":"Santos, N., Gummadi, K.P., and Rodrigues, R. (2009, January 14\u201319). Towards Trusted Cloud Computing. Proceedings of the 2009 Conference on Hot Topics in Cloud Computing (Hotcloud), San Diego, CA, USA."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Ouedraogo, M., Severine, M., Herve, C., Steven, F., and Eric, D. (2015). Security Transparency: The Next Frontier for Security Research in the Cloud. J. Cloud Comput.","DOI":"10.1186\/s13677-015-0037-5"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Ouedraogo, M., Dubois, E., Khadraoui, D., Poggi, S., and Chenal, B. (2015, January 20\u201322). Adopting an agent and event driven approach for enabling mutual auditability and security transparency in cloud based services. Proceedings of the International Conference on Cloud Computing and Services Science, Lisbon, Portugal.","DOI":"10.5220\/0005496205650572"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Casola, V., Benedictis, A., and Rak, M. (2015, January 24\u201327). Security monitoring in the Cloud: An SLA-based approach. Proceedings of the 10th IEEE International Conference on Availability, Reliability and Security (ARES), Toulouse, France.","DOI":"10.1109\/ARES.2015.74"},{"key":"ref_9","unstructured":"Happe, J., Theilmann, W., Edmonds, A., and Kearney, K. (2011). Service Level Agreements for Cloud Computing, Springer Service-Business Media."},{"key":"ref_10","unstructured":"Krautheim, J.F. (2009, January 14\u201319). Private Virtual Infrastructure for Cloud Computing. Proceedings of the Hotcloud Conference 2009, San Diego, CA, USA."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Theilman, W., Yahyapour, R., and Butler, J. (2008, January 10\u201313). Multi-level SLA management for service oriented infrastructures. Proceedings of the 1st European Conference on Towards a Service-Based Internet, Madrid, Spain.","DOI":"10.1007\/978-3-540-89897-9_28"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"313","DOI":"10.3233\/MGS-2007-3304","article-title":"Towards Autonomous SLA Management using a Proxy-Like Approach","volume":"3","author":"Koller","year":"2007","journal-title":"Multiagent Grid Syst."},{"key":"ref_13","unstructured":"Cloud Security Alliance CloudAudit Security, Trust & Assurance Registry (STAR). Available online: https:\/\/cloudsecurityalliance.org\/star\/certification\/."},{"key":"ref_14","unstructured":"Jaydip, S. (2013). Architectures and Protocols for Secure Information Technology, Information Science Reference."},{"key":"ref_15","first-page":"148","article-title":"The impact of IT on Market Information and Transparency: A Unified Theoretical Framework","volume":"7","author":"Granados","year":"2006","journal-title":"J. Assoc. Inf. Syst."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"207","DOI":"10.1111\/j.1475-679X.2004.00136.x","article-title":"What Determines Corporate Transparency?","volume":"2","author":"Bushman","year":"2004","journal-title":"J. Account. Res."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Kopits, G., and Jon, C. (1998). Transparency in Government Operation, International Monetary Fund. IMF Occasional Paper, No. 158.","DOI":"10.5089\/9781557756978.084"},{"key":"ref_18","unstructured":"Andrews, S. What is Security Transparency?. Available online: http:\/\/www.zdnet.com\/article\/what-is-security-transparency\/."},{"key":"ref_19","unstructured":"Aslam, M. (2014). Bringing Visibility in the Clouds. [Ph.D. Thesis, Swedish Institute of Computer Science]."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"299","DOI":"10.1007\/s00766-013-0166-7","article-title":"Evaluating Cloud Deployment Scenarios Based on Security and Privacy Requirements","volume":"18","author":"Kalloniatis","year":"2013","journal-title":"Requirements Eng."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"759","DOI":"10.1016\/j.csi.2013.12.010","article-title":"Towards the Design of Secure and Privacy-Oriented Information Systems in the Cloud: Identifying the major concepts","volume":"36","author":"Kalloniatis","year":"2014","journal-title":"Comput. Stand. Interfaces"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1109\/MSP.2010.140","article-title":"Cloud Provider Transaprency: An Empirical Evaluation","volume":"8","author":"Pauley","year":"2010","journal-title":"IEEE Secur. Priv."},{"key":"ref_23","unstructured":"Doelitzscher, F., Reich, C., Knahl, M., and Clark, N. (2013). Computer Communications and Networks, Springer. Chapter Privacy and Security for Cloud Computing."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"65","DOI":"10.1146\/annurev-polisci-032210-144356","article-title":"Does transparency improve governance?","volume":"17","author":"Kosack","year":"2014","journal-title":"Annu. Rev. Political Sci."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"117","DOI":"10.1016\/j.infsof.2013.06.003","article-title":"An Empirical Study on the Implementation and Evaluation of a Goal-driven Software Development Risk Management Model","volume":"56","author":"Islam","year":"2014","journal-title":"J. Inf. Softw. Technol."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/8\/1\/5\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T19:19:14Z","timestamp":1760210354000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/8\/1\/5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,2,17]]},"references-count":25,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2016,3]]}},"alternative-id":["fi8010005"],"URL":"https:\/\/doi.org\/10.3390\/fi8010005","relation":{},"ISSN":["1999-5903"],"issn-type":[{"type":"electronic","value":"1999-5903"}],"subject":[],"published":{"date-parts":[[2016,2,17]]}}}