{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T14:29:23Z","timestamp":1781101763259,"version":"3.54.1"},"reference-count":30,"publisher":"IGI Global Scientific Publishing","issue":"1","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2015,1]]},"abstract":"<jats:p>To benefit from cloud computing and the advantages it offers, obstacles regarding the usage and acceptance of clouds have to be cleared. For cloud providers, one way to obtain customers' confidence is to establish security mechanisms when using clouds. The ISO 27001 standard provides general concepts for establishing information security in an organization. Risk analysis is an essential part in the ISO 27001 standard for achieving information security. This standard, however, contains ambiguous descriptions. In addition, it does not stipulate any method to identify assets, threats, and vulnerabilities. In this paper, the authors present a method for cloud computing systems to perform risk analysis according to the ISO 27001. The authors' structured method is tailored to SMEs. It relies upon patterns to describe context and structure of a cloud computing system, elicit security requirements, identify threats, and select controls, which ease the effort for these activities. The authors' method guides companies through the process of risk analysis in a structured manner. Furthermore, the authors provide a model-based tool for supporting the ISO 27001 standard certification. The authors' tool consists of various plug-ins for conducting different steps of their method.<\/jats:p>","DOI":"10.4018\/ijsse.2015010102","type":"journal-article","created":{"date-parts":[[2015,2,13]],"date-time":"2015-02-13T08:30:39Z","timestamp":1423816239000},"page":"24-46","source":"Crossref","is-referenced-by-count":2,"title":["A Pattern-Based and Tool-Supported Risk Analysis Method Compliant to ISO 27001 for Cloud Systems"],"prefix":"10.4018","volume":"6","author":[{"given":"Azadeh","family":"Alebrahim","sequence":"first","affiliation":[{"name":"Paluno \u2013 The Ruhr Institute for Software Technology, University of Duisburg-Essen, Duisburg, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Denis","family":"Hatebur","sequence":"additional","affiliation":[{"name":"The Ruhr Institute for Software Technology, University of Duisburg-Essen, Duisburg, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Stephan","family":"Fassbender","sequence":"additional","affiliation":[{"name":"The Ruhr Institute for Software Technology, University of Duisburg-Essen, Duisburg, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ludger","family":"Goeke","sequence":"additional","affiliation":[{"name":"ITESYS Inst. f. tech. Sys. GmbH, Dortmund, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Isabelle","family":"C\u00f4t\u00e9","sequence":"additional","affiliation":[{"name":"ITESYS Inst. f. tech. Sys. GmbH, Dortmund, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"ijsse.2015010102-0","author":"C.Alberts","year":"2002","journal-title":"Managing Information Security Risks: The OCTAVE (SM) Approach"},{"key":"ijsse.2015010102-1","author":"M.Armbrust","year":"2009","journal-title":"Above the clouds: A berkeley view of cloud computing (Tech. Rep.)"},{"issue":"4","key":"ijsse.2015010102-2","first-page":"1","article-title":"A pattern-based method for establishing a cloud-specific information security management system.","volume":"18","author":"K.Beckers","year":"2013","journal-title":"Requirements Engineering"},{"key":"ijsse.2015010102-3","doi-asserted-by":"publisher","DOI":"10.1145\/2554850.2554921"},{"key":"ijsse.2015010102-4","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2013.61"},{"key":"ijsse.2015010102-5","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-07452-8_13"},{"key":"ijsse.2015010102-6","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2011.55"},{"key":"ijsse.2015010102-7","unstructured":"BSI transition guide. Retrieved October 28, 2014, from http:\/\/www.bsigroup.com\/LocalFiles\/en-GB\/iso-iec-27001\/resources\/BSI-ISO27001-transition-guide-UK-EN-pdf.pdf"},{"key":"ijsse.2015010102-8","author":"F.Buschmann","year":"1996","journal-title":"Pattern-Oriented Software Architecture: A System of Patterns"},{"key":"ijsse.2015010102-9","unstructured":"Cloud, I. D. C. Retrieved January 14, 2014, from https:\/\/www-304.ibm.com\/isv\/library\/pdfs\/cloud_idc.pdf"},{"key":"ijsse.2015010102-10","unstructured":"Cloud Controls Matrix (CCM). Retrieved October 28, 2014, from https:\/\/cloudsecurityalliance.org\/research\/ccm"},{"key":"ijsse.2015010102-11","unstructured":"ClouDAT project. Retrieved October 28, 2014, from http:\/\/www.cloudat.de"},{"key":"ijsse.2015010102-12","unstructured":"CSA. (2011). Security guidance for critical areas of focus in cloud computing (v. 3.0)."},{"key":"ijsse.2015010102-13","unstructured":"Eclipse Framework. Retrieved October 28, 2014, from http:\/\/www.eclipse.org"},{"key":"ijsse.2015010102-14","unstructured":"Eclipse Modeling Framework (EMF). Retrieved October 28, 2014, from http:\/\/www.eclipse.org\/modeling\/emf"},{"key":"ijsse.2015010102-15","unstructured":"Elky, S. (2006). An Introduction to Information Security Risk Management. Retrieved October 28, 2014, from http:\/\/www.sans.org\/reading-room\/whitepapers\/auditing\/introduction-information-system-risk-management-1204"},{"key":"ijsse.2015010102-16","unstructured":"Epsilon Framework. Retrieved October 28, 2014, from http:\/\/www.eclipse.org\/epsilon"},{"key":"ijsse.2015010102-17","unstructured":"European Network and Information Security Agency. (2009). Cloud computing \u2013 benefits, risks and recommendations for information security."},{"key":"ijsse.2015010102-18","doi-asserted-by":"crossref","unstructured":"Fabian, B., G\u00fcrses S., Heisel, M., Santen, T., & Schmidt, H. (2010). A comparison of security requirements engineering methods. Requirements Engineering \u2013 Special Issue on Security Requirements Engineering, 15(1), 7-40.","DOI":"10.1007\/s00766-009-0092-x"},{"key":"ijsse.2015010102-19","doi-asserted-by":"publisher","DOI":"10.1145\/2000799.2000802"},{"key":"ijsse.2015010102-20","unstructured":"Heiser, J., & Nicolett, M. (2008). Assessing the security risks of cloud computing."},{"key":"ijsse.2015010102-21","unstructured":"International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC). (2005). ISO\/IEC 27001: Information technology \u2013 Security techniques \u2013 Information security management systems \u2013 Requirements."},{"key":"ijsse.2015010102-22","unstructured":"International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC). (2011). ISO\/IEC 27005: Information technology \u2013 Security techniques \u2013 Information security risk management."},{"key":"ijsse.2015010102-23","unstructured":"International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC). (2013). ISO\/IEC 27002: Information technology \u2013 Security techniques \u2013 Code of practice for information security controls."},{"key":"ijsse.2015010102-24","unstructured":"International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC). (2013). ISO\/IEC: 27001: Information technology \u2013 Security techniques \u2013 Information security management systems \u2013 Requirements."},{"key":"ijsse.2015010102-25","unstructured":"LANFER SYSTEMHAUS. Retrieved October 28, 2014, from http:\/\/www.lanfer-systemhaus.de"},{"key":"ijsse.2015010102-26","author":"M. S.Lund","year":"2010","journal-title":"Model-Driven Risk Analysis. The CORAS Approach"},{"key":"ijsse.2015010102-27","author":"P.Mell","year":"2011","journal-title":"800-145. The NIST definition of cloud computing. Gaithersburg, MD, United States: National Institute of Standards and Technology"},{"key":"ijsse.2015010102-28","year":"2006","journal-title":"The security risk management guide"},{"key":"ijsse.2015010102-29","unstructured":"Sirius Framework. Retrieved October 28, 2014, from http:\/\/www.eclipse.org\/sirius"}],"container-title":["International Journal of Secure Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=123453","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2018,11,20]],"date-time":"2018-11-20T21:40:32Z","timestamp":1542750032000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/ijsse.2015010102"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2015,1]]},"references-count":30,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.4018\/ijsse.2015010102","relation":{},"ISSN":["1947-3036","1947-3044"],"issn-type":[{"value":"1947-3036","type":"print"},{"value":"1947-3044","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,1]]}}}