{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,28]],"date-time":"2026-05-28T01:00:33Z","timestamp":1779930033566,"version":"3.53.1"},"reference-count":30,"publisher":"MDPI AG","issue":"11","license":[{"start":{"date-parts":[[2021,11,19]],"date-time":"2021-11-19T00:00:00Z","timestamp":1637280000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001871","name":"Funda\u00e7\u00e3o para a Ci\u00eancia e Tecnologia","doi-asserted-by":"publisher","award":["FCT UIDB\/04466\/2020"],"award-info":[{"award-number":["FCT UIDB\/04466\/2020"]}],"id":[{"id":"10.13039\/501100001871","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001871","name":"Funda\u00e7\u00e3o para a Ci\u00eancia e Tecnologia","doi-asserted-by":"publisher","award":["FCT UIDP\/04466\/2020"],"award-info":[{"award-number":["FCT UIDP\/04466\/2020"]}],"id":[{"id":"10.13039\/501100001871","id-type":"DOI","asserted-by":"publisher"}]},{"name":"dtec.bw","award":["LIONS"],"award-info":[{"award-number":["LIONS"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information"],"abstract":"<jats:p>Today, many products and solutions are provided on the cloud; however, the amount and financial losses due to cloud security incidents illustrate the critical need to do more to protect cloud assets adequately. A gap lies in transferring what cloud and security standards recommend and require to industry practitioners working in the front line. It is of paramount importance to raise awareness about cloud security of these industrial practitioners. Under the guidance of design science paradigm, we introduce a serious game to help participants understand the inherent risks, understand the different roles, and encourage proactive defensive thinking in defending cloud assets. In our game, we designed and implemented an automated evaluator as a novel element. We invite the players to build defense plans and attack plans for which the evaluator calculates success likelihoods. The primary target group is industry practitioners, whereas people with limited background knowledge about cloud security can also participate in and benefit from the game. We design the game and organize several trial runs in an industrial setting. Observations of the trial runs and collected feedback indicate that the game ideas and logic are useful and provide help in raising awareness of cloud security in industry. Our preliminary results share insight into the design of the serious game and are discussed in this paper.<\/jats:p>","DOI":"10.3390\/info12110482","type":"journal-article","created":{"date-parts":[[2021,11,21]],"date-time":"2021-11-21T20:58:21Z","timestamp":1637528301000},"page":"482","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["Raising Awareness about Cloud Security in Industry through a Board Game"],"prefix":"10.3390","volume":"12","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1518-4730","authenticated-orcid":false,"given":"Tiange","family":"Zhao","sequence":"first","affiliation":[{"name":"Siemens AG, 81739 Munich, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1462-6701","authenticated-orcid":false,"given":"Tiago","family":"Gasiba","sequence":"additional","affiliation":[{"name":"Siemens AG, 81739 Munich, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4286-3184","authenticated-orcid":false,"given":"Ulrike","family":"Lechner","sequence":"additional","affiliation":[{"name":"Computer Science, Universit\u00e4t der Bundeswehr M\u00fcnchen, 85579 Munich, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2725-7629","authenticated-orcid":false,"given":"Maria","family":"Pinto-Albuquerque","sequence":"additional","affiliation":[{"name":"Instituto Universit\u00e1rio de Lisboa (ISCTE-IUL), ISTAR, 1649-026 Lisbon, Portugal"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2021,11,19]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Petrik, D., and Herzwurm, G. (2019, January 26). TiIoT ecosystem development through boundary resources: A Siemens MindSphere case study. Proceedings of the 2nd ACM SIGSOFT International Workshop on Software-Intensive Business: Start-Ups, Platforms, and Ecosystems, Sokos Hotel Viru, Tallinn, Estonia.","DOI":"10.1145\/3340481.3342730"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"178","DOI":"10.3325\/cmj.2018.59.178","article-title":"Digital mediators as key enablers of navigation toward health in knowledge landscapes","volume":"59","author":"Simunic","year":"2018","journal-title":"Croat. Med. J."},{"key":"ref_3","unstructured":"(2021, February 15). Top Threats to Cloud Computing: Egregious Eleven Deep Dive. Available online: https:\/\/cloudsecurityalliance.org\/artifacts\/top-threats-egregious-11-deep-dive\/."},{"key":"ref_4","unstructured":"(2021, November 15). UpGuard Team: Black Box, Red Disk: How Top Secret NSA and Army DataLeaked Online. Available online: https:\/\/www.upguard.com\/breaches\/cloud-leak-inscom."},{"key":"ref_5","unstructured":"(2021, November 15). Paladion: Poorly Configured S3 Buckets\u2014A Hacker\u2019s Delight. Available online: https:\/\/www.paladion.net\/blogs\/poorly-configured-s3-buckets-a-hackers-delight."},{"key":"ref_6","unstructured":"(2021, November 15). Michael Scheffler, Datensicherheit in der Cloud: Best Practices Gegen Man-in-the-Cloud-Attacken. Available online: https:\/\/tinyurl.com\/h2u3ky."},{"key":"ref_7","unstructured":"(2020, March 12). Requirements for Bodies Providing STAR Certification. Available online: https:\/\/cloudsecurityalliance.org\/artifacts\/requirements-for-bodies-providing-star-certification\/."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Di Giulio, C., Sprabery, R., Kamhoua, C., Kwiat, K., Campbell, R.H., and Bashir, M.N. (2017, January 25\u201330). Cloud standards in comparison: Are new security frameworks improving cloud security?. Proceedings of the 2017 IEEE 10th International Conference on Cloud Computing (CLOUD), Honolulu, HI, USA.","DOI":"10.1109\/CLOUD.2017.16"},{"key":"ref_9","unstructured":"Zhao, T., Gasiba, T.E., Lechner, U., and Pinto-Albuquerque, M. (2021, January 27\u201328). Exploring a Board Game to Improve Cloud Security Training in Industry. Proceedings of the Second International Computer Programming Education Conference (ICPEC 2021), Online."},{"key":"ref_10","unstructured":"(2020, February 16). Cloud Controls Matrix v4. Available online: https:\/\/cloudsecurityalliance.org\/artifacts\/cloud-controls-matrix-v4\/."},{"key":"ref_11","unstructured":"(2017, July 26). Security Guidance for Critical Areas of Focus in Cloud Computing v4.0. Available online: https:\/\/cloudsecurityalliance.org\/artifacts\/security-guidance-v4\/."},{"key":"ref_12","unstructured":"(2021, October 22). ISO\/IEC 27001 Information Security Management. Available online: https:\/\/www.iso.org\/isoiec-27001-information-security.html."},{"key":"ref_13","unstructured":"(2021, February 16). Cloud Matrix. Available online: https:\/\/attack.mitre.org\/versions\/v8\/matrices\/enterprise\/cloud\/."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Mu\u00f1oz, A., Ma\u00f1a, A., and Gonz\u00e1lez, J. (2013). Dynamic Security Properties Monitoring Architecture for Cloud Computing. Security Engineering for Cloud Computing: Approaches and Tools, IGI Global.","DOI":"10.4018\/978-1-4666-2125-1.ch001"},{"key":"ref_15","unstructured":"Popovi\u0107, K., and Hocenski, \u017d. (2010, January 24\u201328). Cloud computing security issues and challenges. Proceedings of the 33rd International Convention Mipro, Opatija, Croatia."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"D\u00f6rner, R., G\u00f6bel, S., Effelsberg, W., and Wiemeyer, J. (2016). Serious Games: Foundations, Concepts and Practice, Springer.","DOI":"10.1007\/978-3-319-40612-1"},{"key":"ref_17","unstructured":"Bundesamt f\u00fcr Sicherheit in der Informationstechnik (2016). BSI IT-Grundschutz-Katalog, Reguvis Fachmedien GmbH. Available online: https:\/\/tinyurl.com\/2vbs3dka."},{"key":"ref_18","first-page":"660","article-title":"A Review of Using Gaming Technology for Cyber-Security Awareness","volume":"6","author":"Alotaibi","year":"2016","journal-title":"Int. J. Innov. Sci. Res."},{"key":"ref_19","unstructured":"(2021, February 16). Tabletop Security Games & Cards. Available online: https:\/\/adam.shostack.org\/games.html."},{"key":"ref_20","unstructured":"Shostack, A. (2014, January 18). Elevation of privilege: Drawing developers into threat modeling. Proceedings of the 2014 {USENIX} Summit on Gaming, Games, and Gamification in Security Education (3GSE 14), San Diego, CA, USA."},{"key":"ref_21","first-page":"521","article-title":"The good, the bad and the ugly: A study of security decisions in a cyber-physical systems game","volume":"5","author":"Frey","year":"2017","journal-title":"IEEE Trans. Softw. Eng."},{"key":"ref_22","unstructured":"(2021, February 16). The NeoSens Training Method: Computer Security Awareness for a Neophyte Audience. Available online: https:\/\/airbus-seclab.github.io\/dnd\/us-16-Romand-Latapie-Dungeons-Dragons-And-Security-wp.pdf."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Beckers, K., and Pape, S. (2016, January 12\u201316). A Serious Game for Eliciting Social Engineering Security Requirements. Proceedings of the 2016 IEEE 24th International Requirements Engineering Conference (RE), Beijing, China.","DOI":"10.1109\/RE.2016.39"},{"key":"ref_24","unstructured":"Gasiba, T., Beckers, K., Suppan, S., and Rezabek, F. (2019, January 23\u201327). On the Requirements for Serious Games geared towards Software Developers in the Industry. Proceedings of the Conference on Requirements Engineering Conference, Jeju Island, Korea."},{"key":"ref_25","unstructured":"Avgeriou, P., and Shepherd, D. (2020). Sifu\u2014A CyberSecurity Awareness Platform with Challenge Assessment and Intelligent Coach. Special Issue of Cyber-Physical System Security of the Cybersecurity Journal, SpringerOpen. Available online: https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-020-00064-4."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Gasiba, T., Lechner, U., and Pinto-Albuquerque, M. (2021). CyberSecurity Challenges: Serious Games for Awareness Training in Industrial Environments. Bundesamt f\u00fcr Sicherheit in der Informationstechnik: Deutschland, Deutschen IT-Sicherheitskongress. Available online: https:\/\/www.secumedia-shop.net\/Deutschland-Digital-Sicher-30-Jahre-BSI.","DOI":"10.1007\/978-3-030-86797-3_25"},{"key":"ref_27","unstructured":"Gasiba, T., Lechner, U., and Pinto-Albuquerque, M. (2021, January 8\u201311). CyberSecurity Challenges for Software Developer Awareness Training in Industrial Environments. Proceedings of the 16th International Conference on Wirtschaftsinformatik, Online. Available online: https:\/\/aisel.aisnet.org\/wi2021\/NInformation12\/Track12\/2."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"75","DOI":"10.2307\/25148625","article-title":"Design science research in information systems","volume":"28","author":"Hevner","year":"2004","journal-title":"MIS Q."},{"key":"ref_29","unstructured":"Gleasure, R. (2021, November 11). What Is a \u2018Wicked Problem\u2019 for Is Research? SIG Prag Workshop on IT Artefact Design & Workpractice Improvement. 2013 Tilburg, The Netherlands. Available online: https:\/\/research.cbs.dk\/en\/publications\/what-is-a-wicked-problem-for-is-research."},{"key":"ref_30","unstructured":"Konva (2021, October 20). JavaScript 2D Canvas Library. Available online: https:\/\/https:\/\/konvajs.org\/."}],"container-title":["Information"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2078-2489\/12\/11\/482\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T07:33:00Z","timestamp":1760167980000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2078-2489\/12\/11\/482"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,11,19]]},"references-count":30,"journal-issue":{"issue":"11","published-online":{"date-parts":[[2021,11]]}},"alternative-id":["info12110482"],"URL":"https:\/\/doi.org\/10.3390\/info12110482","relation":{},"ISSN":["2078-2489"],"issn-type":[{"value":"2078-2489","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,11,19]]}}}