{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T17:01:25Z","timestamp":1781110885693,"version":"3.54.1"},"reference-count":26,"publisher":"IGI Global Scientific Publishing","issue":"2","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014,4]]},"abstract":"<jats:p>Cloud computing systems offer an attractive alternative to traditional IT-systems, because of economic benefits that arise from the cloud's scalable and flexible IT-resources. The benefits are of particular interest for SME's. The reason is that using Cloud Resources allows an SME to focus on its core business rather than on IT-resources. However, numerous concerns about the security of cloud computing services exist. Potential cloud customers have to be confident that the cloud services they acquire are secure for them to use. Therefore, they have to have a clear set of security requirements covering their security needs. Eliciting these requirements is a difficult task, because of the amount of stakeholders and technical components to consider in a cloud environment. Therefore, the authors propose a structured, pattern-based method supporting eliciting security requirements and selecting security measures. The method guides potential cloud customers to model the application of their business case in a cloud computing context using a pattern-based approach. Thus, a potential cloud customer can instantiate our so-called Cloud System Analysis Pattern. Then, the information of the instantiated pattern can be used to fill-out our textual security requirements patterns and individual defined security requirement patterns, as well. The presented method is tool-supported. Our tool supports the instantiation of the cloud system analysis pattern and automatically transfers the information from the instance to the security requirements patterns. In addition, they have validation conditions that check e.g., if a security requirement refers to at least one element in the cloud. The authors illustrate their method using an online-banking system as running example.<\/jats:p>","DOI":"10.4018\/ijsse.2014040102","type":"journal-article","created":{"date-parts":[[2014,9,2]],"date-time":"2014-09-02T09:06:38Z","timestamp":1409648798000},"page":"20-43","source":"Crossref","is-referenced-by-count":7,"title":["A Structured Method for Security Requirements Elicitation concerning the Cloud Computing Domain"],"prefix":"10.4018","volume":"5","author":[{"given":"Kristian","family":"Beckers","sequence":"first","affiliation":[{"name":"Univeristy of Duisburg-Essen, Essen, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Isabelle","family":"C\u00f4t\u00e9","sequence":"additional","affiliation":[{"name":"ITESYS Institute for Technical Systems GmbH, Dortmund, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ludger","family":"Goeke","sequence":"additional","affiliation":[{"name":"ITESYS Institute for Technical Systems GmbH, Dortmund, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Selim","family":"G\u00fcler","sequence":"additional","affiliation":[{"name":"EASY SOFTWARE AG, M\u00fclheim an der Ruhr, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Maritta","family":"Heisel","sequence":"additional","affiliation":[{"name":"University of Duisburg-Essen, Essen, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"ijsse.2014040102-0","author":"C.Alexander","year":"1978","journal-title":"A pattern language: Towns, buildings, construction"},{"key":"ijsse.2014040102-1","unstructured":"Armbrust, M., Fox, A., Griffith, R., Joseph, A. D., Katz, R. H., & Konwinski, A. \u2026 Zaharia, M. (2009). Above the clouds: A Berkeley view of cloud computing. Technical Report, Berkeley University."},{"key":"ijsse.2014040102-2"},{"key":"ijsse.2014040102-3","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2011.55"},{"key":"ijsse.2014040102-4","year":"2009","journal-title":"Security guidance for critical areas of focus in cloud computing"},{"key":"ijsse.2014040102-5","year":"2010","journal-title":"Top threats to cloud computing"},{"key":"ijsse.2014040102-6","unstructured":"Eclipse Foundation. (2011). Eclipse - An open development platform. Retrieved from http:\/\/www.eclipse.org\/"},{"key":"ijsse.2014040102-7","unstructured":"Eclipse Foundation. (2011). Eclipse graphical modeling framework (GMF). Retrieved from http:\/\/www.eclipse.org\/modeling\/gmf\/"},{"key":"ijsse.2014040102-8","unstructured":"Eclipse Foundation. (2011). Graphical editing framework project (GEF). Retrieved from http:\/\/www.eclipse.org\/gef\/"},{"key":"ijsse.2014040102-9","unstructured":"Eclipse Foundation. (2012). Eclipse modeling framework project (EMF). Retrieved from http:\/\/www.eclipse.org\/modeling\/emf\/"},{"key":"ijsse.2014040102-10","year":"2009","journal-title":"Cloud computing - benefits, risks and recommendations for information security"},{"key":"ijsse.2014040102-11","doi-asserted-by":"crossref","unstructured":"Fabian, B., G\u00fcrses, S., Heisel, M., Santen, T., & Schmidt, H. (2010). A comparison of security requirements engineering methods. Requirements Engineering \u2013 Special Issue on Security Requirements Engineering, 15(1), 7\u201340. Springer.","DOI":"10.1007\/s00766-009-0092-x"},{"key":"ijsse.2014040102-12"},{"key":"ijsse.2014040102-13","author":"M.Fowler","year":"1996","journal-title":"Analysis patterns: Reusable object models"},{"key":"ijsse.2014040102-14","author":"E.Gamma","year":"1994","journal-title":"Design patterns: Elements of reusable object-oriented software"},{"key":"ijsse.2014040102-15","year":"2012","journal-title":"Security recommendations for cloud computing providers"},{"key":"ijsse.2014040102-16"},{"key":"ijsse.2014040102-17"},{"key":"ijsse.2014040102-18","author":"J.Heiser","year":"2008","journal-title":"Assessing the security risks of cloud computing"},{"key":"ijsse.2014040102-19","unstructured":"International Organization for Standardization (ISO) and International Electrotechnical Commission. (IEC) (2005). ISO 27001- Information technology - Security techniques - Information security management systems - Requirements. Geneva, Switzerland: ISO."},{"key":"ijsse.2014040102-20","author":"M.Jackson","year":"2001","journal-title":"Problem frames - Analyzing and structuring software development problems"},{"key":"ijsse.2014040102-21","unstructured":"Mell, P., & Grance, T. (2011). The NIST definition of cloud computing (Special Publication 800-145). Gaithersburg, MD: The National Institute of Standards and Technology (NIST)."},{"key":"ijsse.2014040102-22","author":"M.Schumacher","year":"2006","journal-title":"Security patterns: Integrating security and systems engineering"},{"key":"ijsse.2014040102-23","unstructured":"UML Revision Task Force. (May 2010). OMG unified modeling language: Superstructure, Object Management Group (OMG)."},{"key":"ijsse.2014040102-24","doi-asserted-by":"crossref","unstructured":"Vaquero, L. M., Rodero-Merino, L., Caceres, J., & Lindner, M. (2008). A break in the clouds: Towards a cloud definition. SIGCOMM Computer Communication Review, 39(1), 50\u201355. New York, NY: ACM.","DOI":"10.1145\/1496091.1496100"},{"key":"ijsse.2014040102-25","author":"S.Withall","year":"2007","journal-title":"Software requirement patterns"}],"container-title":["International Journal of Secure Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=113725","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2018,11,20]],"date-time":"2018-11-20T21:39:29Z","timestamp":1542749969000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/ijsse.2014040102"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2014,4]]},"references-count":26,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.4018\/ijsse.2014040102","relation":{},"ISSN":["1947-3036","1947-3044"],"issn-type":[{"value":"1947-3036","type":"print"},{"value":"1947-3044","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014,4]]}}}