1
Developing a Cloud Computing Risk Assessment Instrument for Small to Medium
Sized Enterprises: A Qualitative Case Study using a Delphi Technique
Chapter 1: Introduction
The information technology (IT) industry is a recent addition to the world of business but
has become a critical part of every enterprise level organization in this century (Jeganathan,
2017). Information technology has become critical to any business over a certain size and has
become a significant part of most large business’ IT budgets (Ring, 2015). IT is a field of truly
breathtaking change, and industry standards for storing company data (Al-Ruithe, Benkhelifa, &
Hameed, 2016), reaching out to customers (Alassafi, Alharthi, Walters, & Wills, 2017), and
creating new value from company assets (Khan & Al-Yasiri, 2016) can change on a frequent
basis. No part of IT is safe from rapid change, including fundamental concepts such as what a
computer is, and where a company should put the computer (Bayramusta & Nasir, 2016; Funk,
2015). A change that is gathering speed in the IT industry that has the potential to disrupt almost
every daily task for cybersecurity professionals is Cloud computing.
Cloud computing at its simplest is using someone else’s computers to perform the
organization’s IT operations (Rao & Selvamani, 2015). Instead of using hardware that the
organization has bought and takes care of, the organization uses virtual servers in an environment
usually built and maintained by another company. Some versions of private Clouds use the
organization’s own hardware, but that is rare, and is more of a semantical redefinition of using
virtual servers in house (Molken & van Wilkins, 2017). Cloud computing as commonly
understood in the IT industry, is a virtual computing environment hosted, maintained, and at least
partially secured by a third party (Lian, Yen, & Wang, 2014). The use of Cloud computing by an
organization allows its IT team to focus on more strategic and business aligned activities and
2
removes physical maintenance and other activities related to owning and caring for computer
servers (Rahul, & Arman, 2017). By adopting Cloud computing, an organization can remove
high cost items from its capital expenditure (CapEx) budget such as server rooms with expensive
cooling and huge electrical needs and replace them with more cost-efficient operating expenses
(OpEx) budget items such as virtual server rentals from Cloud service providers (CSP)
(Mangiuc, 2017).
Although cost savings are a primary driver for many organizations that adopt Cloud
computing, the reasons why there is need for more research on Cloud computing is much more
interesting (Bayramusta & Nasir, 2016). Cloud computing is rapidly changing the fundamental
underlying foundational paradigms of IT and how businesses use IT (Chatman, 2010;
Hosseinian-Far, Ramachandran, Sarwar, 2017; Wang, Wood, Abdul-Rahman, & Lee, 2016). Even
though IT is a new and fast-moving field compared to most parts of business, Cloud computing
is an even more powerful change agent. Many careers in IT are changing or disappearing
because of Cloud computing (Khan, Nicho, & Takruri, 2016). Basic ideas in IT such as what
describes a server most accurately, or how an IT business process comes to fruition, change very
rapidly because of Cloud computing (El Makkaoui, Ezzati, Beni-Hssane, &
Motamed, 2016). The primary constraint that has prevented some organizations from adopting
Cloud computing is the security of the organization’s data in the Cloud (Ring, 2015). One of the
most important business processes that organizations can use to evaluate and resolve Cloud
security concerns is risk assessment and analysis (Damenu & Balakrishma, 2015; Viehmann,
2014; Weintraub & Cohen, 2016). Researching ways organizations successfully address these
3
security concerns is an important contribution to the industry and the academic field of research
(Alassafi, Alharthi, Walters, & Wills, 2017; Al-Ruithe, Benkhelifa, & Hameed, 2016; Ray, 2016).
There are multiple academic and practical approaches to securing Cloud computing environments
(Aljawarneh, Alawneh, & Jaradat, 2016; Casola, De Benedictis, Rak, & Rio, 2016;
Choi & Lee, 2015). Many solutions rely on organizations trusting the CSP (Trapero, Modic,
Stopar, Taha, & Sur, 2017). Organizations that do not trust their CSPs or other vendors to provide
complete Cloud security either by mandate or by common business practice (Cayirci, Garaga,
Santana de Oliveira, & Roudier, 2016; Preeti, Runni, & Manjula, 2016) need a different
approach. Organizations that modify or adapt their current business practices or the Cloud
computing environment the organization uses, may provide a useful template for future academic
research into Cloud security.
Statement of the Problem
The researcher used this study to address the problem that there is no commonly
understood and adopted best practice standard for small to medium sized enterprises (SMEs) on
how to specifically assess security risks relating to the Cloud (Coppolino, D’Antonio, Mazzeo, &
Romano, 2016; El Makkaoui, Ezzati, Beni-Hssane, & Motamed, 2016; Raza, Rashid, & Awan,
2017). Existing business processes and industry frameworks follow a design created for larger,
on premise environments and as such, do not effectively address Cloud computing security
concerns for smaller organizations (El-Gazzar, Hustad, & Olsen, 2016; Gleeson & Walden,
2016). To date, larger organizations are relying on Cloud Service Providers (CSPs) to supply
their own security tools (Jaatun, Pearson, Gittler, Leenes, & Niezen, 2015), Service Level
Agreements (SLAs) (Barrow, Kumari, & Manjula, 2016), better Cloud services customer
education (Paxton, 2016), new data classification laws and regulations (Gleeson & Walden,
4
2016), comprehensive security and management frameworks (Raza, Rashid, & Awan, 2017), and
a myriad of tailored solutions to specific problems, leaving a baseline that could be leveraged by
lesser sized organizations for Cloud security risk assessment to be addressed by others. SMEs
have slowed their adoption of Cloud computing even though Cloud computing improves many
business processes and offers significant savings (Issa, Abdallah, & Muhammad, 2014; Khan,
Nicho, & Takruri, 2016). There are several interesting academic solutions to Cloud security
issues published (Alasaffi, Alharthi, Walters, & Wills, 2017; Al-Ruithe, Benkhelifa, & Hameed,
2016; Gleeson & Walden, 2016), but rarely a case of a solution adopted in the corporate world
that a smaller sized organization could leverage (Rebello, Mellado, Fernandez-Medina, &
Mouratidis, 2014); these studies do not build upon current industry best practices and are not
viable for most organizations. Organizations that are adopting Cloud computing are facing these
new security issues without a consensus solution that all organizations, regardless of their size
can use (Coppolino, D’Antonio, Mazzeo, & Romano, 2016; El Makkaoui, Ezzati, Beni-Hssane,
& Motamed, 2016; Raza, Rashid, & Awan, 2017).
Purpose of the Study
The purpose of this qualitative case study-based research study was to discover an
underlying framework for research in SME risk analysis for Cloud computing and to create a
validated instrument that SMEs can use to assess their risk in Cloud adoption. Unlike SMEs, the
vast majority of medium to large enterprises use risk assessments before adopting new
computing environments (Cayirci, Garaga, Santana de Oliveira, & Roudier, 2016; Jouini &
Rabai, 2016). SMEs need a process or validated instrument such as a risk assessment to
determine if they should move to the Cloud (Bildosola, Rio-Belver, Cilleruelo, & Garechana,
2015; Carcary, Doherty, & Conway, 2014; Hasheela, Smolander, & Mufeti, 2016). Research
5
shows that SMEs using a risk-based approach have not reached a consensus on how to identify
and address Cloud security risks (Carcary, Doherty, Conway, & McLaughlin, 2014; Kumar,
Samalia, & Verma, 2017). The target population for this research study was risk professionals
that were either employed by or contracted to SMEs to perform Cloud security risk assessments.
Members of a Washington D.C. area chapter of a professional risk association represent
the target population and the sample population consisted of those chapter members that respond
to the web survey. The population of risk experts in the chapter is approximately three thousand
members. This research study used a web survey predicated on a Delphi technique with two or
three rounds as the method to gather data from a group of IT risk experts based on membership
in the Washington D.C. area local chapter of ISACA. ISACA is a global organization of
information systems auditors and risk assessors. ISACA publishes information security
governance and risk assessment guides including COBIT (ISACA GWDC, 2018). Recent
studies using a Delphi technique show useful results with sample population sizes of forty or
fewer participants (Choi & Lee, 2015; El-Gazzar, Hustad, & Olsen, 2016; Johnson, 2009). With a
potential population of approximately three thousand and a participation rate as low as one per
cent, the resulting sample size of close to thirty experts was more than enough to complete the
research study and return useful results. Using case study procedures, this research study
addressed the concerns of SMEs looking at Cloud adoption (Glaser, 2016). Case study review
and analysis was the procedure inductively used to create a thesis from the survey results. A risk
assessment instrument for SMEs follows from the generated theory.
Theoretical Conceptual Framework
The underlying conceptual framework for this research study is that SMEs have different
needs than large enterprises regarding Cloud computing environment risk assessments, and
6
academic research has not answered those needs yet. Cloud environment risk assessments create
new problems for organizations of all sizes (Assante, Castro, Hamburg, & Martin, 2016;
Hussain, Hussain, Hussain, Damiani, & Chang, 2017). While SMEs of different regions may
have distinct issues (Bildosola, Rio-Belver, Cilleruelo, & Garechana, 2015; Carcary, Doherty, &
Conway, 2014; Kumar, Samalia, & Verma, 2014), a common factor for all SMEs is that SMEs
have greater challenges solving these problems as SMEs have less resources and fewer skilled
employees to resolve Cloud computing risk assessment issues (Assante, Castro, Hamburg, &
Martin, 2016; Carcary, Doherty, & Conway, 2014; Chiregi & Navimipour, 2017). A common
factor for all SMEs is that many academic solutions to properly risk assessing Cloud computing
environments require highly technical knowledge and skills (Hasheela, Smolander, & Mufeti,
2016; Kumar, Samalia, & Verma, 2017) or large budgets (Mayadunne & Park, 2016; Moyo &
Loock, 2016). While properly deployed large enterprise solutions may show positive results if
used by SMEs, the cost in both employee skills and financial outlay prohibit these solutions in
the real world (Bildosoia, Rio-Belver, Cillerueio, & Garechana, 2015; Carcary, Doherty,
Conway, & McLaughlin, 2014). Appropriate solutions for large multi-national enterprises are not
the correct answer for SMEs.
The smaller budgets of SMEs require Cloud environment risk assessments that not only
require smaller initial cost or capital expenditures (CapEx), but also require small to no
continuing costs or operating expenses (OpEx). Academic solutions to Cloud environment risk
assessment needs that cannot exist in the smaller confines of the SME world, do not contribute to
the field of SME Cloud computing environment risk assessments. While foundational research
that indicates SMEs need workable Cloud computing environment risk assessments is present
(Lacity & Reynolds, 2014; Phaphoom, Wang, Samuel, Helmer, & Abrahamsson, 2015;
7
Priyadarshinee, Raut, Jha, & Kamble, 2017), the next step of addressing the need is not yet
current (Trapero, Modic, Stopar, Taha, & Suri, 2017; Wang, Wood, Abdul-Rahman, & Lee,
2016). Addressing the need of SMEs to properly assess the risk of using Cloud computing
environments is a new field of research hampered by factors unique to the SME paradigm. Due
to the reduced levels of skill and budget amounts available to SMEs, the research for SME Cloud
computing risk assessments must focus on simpler ways to assess and reduce the risk of Cloud
computing adoption. This research study attempted to supply a workable risk assessment
instrument based on research that other researchers can extend and amplify going forward.
Nature of the Study
A qualitative approach using a case study methodology is the best solution as the theory
relating to a successful Cloud computing risk assessment does not yet exist. A problem solved by
using a qualitative case study approach is that the subject population of risk-based Cloud
computing research experts were able to respond with qualitative data but not quantitative
numbers to avoid compromising their organization’s security (Beauchamp, 2015). Even though
the audience for this research study commonly works in quantitative ways, the audience will find
value in qualitative case study research on this topic (Liu, Chan, & Ran, 2016). A truly
experimental design for this research study was not feasible as the topic is not a general one, and
a random selection of the population would not possess the requisite knowledge needed to
address the topic of Cloud security. Even narrowing the population to that of cybersecurity
engineers, Cloud computing expertise is in short supply, and Cloud computing security even
more so (Khan, Nicho, & Takruri, 2016).
Other qualitative research approaches lack the flexibility needed to discover and refine a
new theory and a validated tool for SMEs from existing industry standards. Ethnographic,
8
phenomenological, or narrative approaches do not work for this research study based on data
regarding Cloud computing risk assessments. A grounded theory approach was not appropriate
for several reasons, but most importantly because of the security of the participating subjects’
organizations. Cybersecurity professionals do not commonly discuss specifics in their fight to
keep their organizations secure, which limits a researcher’s ability to ask questions and develop
connections during a coding process (Rebello, Mellado, Fernandez-Medina, & Mouratidis,
2014). If details of the cybersecurity professionals’ organizations’ defenses are common
knowledge, then their adversaries gain an advantage. This organizational security concern is also
the primary factor regarding ethical concerns for this research study.
The proposed case study research study design includes use of the Delphi technique. The
RAND Corporation created the Delphi technique to facilitate the collation and distillation of
expert opinions in a field (Hsu & Sanford, 2007). The Delphi technique seems well designed for
the Internet with current researchers using “eDelphi” based web surveys (Gill, Leslie, Grech, &
Latour, 2013). Although Cloud security is a very new field, some illustrative research is evident
in the field using Delphi techniques (Choi & Lee, 2015; El-Gazzar, Hustad, & Olsen, 2016; Liu,
Chan, & Ran, 2016). These studies use the Delphi technique in different manners, but similar to
this proposed research study, all rely on electronic communications with groups of experts.
Although the research topic is very specialized compared to some business research
topics, the topic is broad enough to select a sample population large enough to meet the needs of
this research study. Using a Delphi technique with two or three rounds of surveys further reduces
the appropriate number of subjects needed for this research study, although Delphi techniques
have subject based issues also. For this research study, ethical concerns focused on protecting the
anonymity of the respondents and their organizations. There is no consensus in the industry or
9
the academic research field on what works for Cloud security (Ring, 2015), so a case study of
even a very successful effort to secure Cloud computing would not have much external validity
or replication interest.
The data collection procedures and data analysis followed accepted Delphi technique
practices. As academic research is still exploring the current state of Cloud security, the
informative value of industry-based practitioners’ tools and techniques is very high (Lynn,
VanDer Werff, Hunt, & Healy, 2016). The researcher employed a Delphi technique to gather and
distill the current frameworks, categories, controls, and recommended mitigation used by a
representative expert group of risk professionals. Although the experts in this research study are
not academics, the results still add to the field of research because the field is so new.
Research Questions
The questions used in the survey elicited details on how organizations adopt current risk
assessment processes and other business procedures used to approve new IT computing
environments, and/or what new paradigms organizations are using. Additionally, by using a
Delphi technique this research study was able to identify if there is a consensus on what works
and if there are processes and procedures that have shown success.
RQ1. What are the current frameworks being leveraged in Cloud specific risk
assessments?
RQ2. What are the primary categories of concern presently being addressed in Cloud
specific risk assessments?
RQ3. What are the commonly used and tailored security controls in Cloud specific risk
assessments?
10
RQ4. What are the commonly recommended mitigations in Cloud specific risk
assessments?
Significance of the Study
This research study is important because it contributes to the academic field of Cloud
computing security risk assessment solutions, and to the security of SMEs adopting Cloud
computing. The answers to the research questions posed by this study have importance to both
SMEs and the academic field. IT risk assessment solutions for on-premises computing have
achieved maturity from an academic viewpoint, but those frameworks and existing IT solutions
are not adequate for Cloud based computing (Coppolino, D’Antonio, Mazzeo, & Romano, 2016;
El Makkaoui, Ezzati, Beni-Hssane, & Motamed, 2016; Raza, Rashid, & Awan, 2017). Even
though researchers have proposed several academic frameworks to improve risk assessments for
Cloud based computing for large enterprises, this research study is one of the first to provide
evidence of which frameworks experts in the field are starting to use. SMEs can use the results of
this research study to better secure their Cloud computing environments. While many non-viable
frameworks are interesting thought experiments and contribute to the body of academic
knowledge, researchers that are interested in real world feedback on proposed Cloud computing
risk assessments solutions will be able to use this research study to provide direction for SMEs.
Researchers can also use this research study as an example of effective Delphi techniques for
research in the Cloud security field.
Industry based professionals will find significance in this research study as it provides
guidance on what expert practitioners are using. The IT field has issues with sharing solutions.
This is because any publication describing organizations security solutions can provide
information that bad actors could use to find weaknesses in the organization’s security (Jouini &
11
Rabai, 2016). Through this research study, the researcher provides pertinent and accurate
information regarding Cloud computing risk assessments that may not be available by other
means.
Definitions of Key Terms
Cloud Data Storage: Cloud storage is a way for organizations to store data on the
Internet as a service instead of using on-premises storage systems. Cloud data storage key
features include standard Cloud features such as just-in-time capacity, and no up-front CapEx
expenditures (Phaphoom, Wang, Samuel, Helmer, & Abrahamsson, 2015)
Cloud Service Provider (CSP): The current term for an organization that offers services
to customers from a remote data center connected via the Internet. Major public CSPs include
AWS, Google, and Microsoft. (Cayirci, Garaga, Santana de Oliveira, & Roudier, 2016).
Security as a Service (SECaaS): Security as a service (SECaaS) is where a third party
provides an organization’s IS needs. Due to the structure of most CSPs, SECaaS is becoming
increasingly important. (Aldorisio, 2018)
Service Level Agreement (SLA): A service-level agreement (SLA) defines the level of
service an organization expects from a third party. Cloud SLAs are becoming an option for an
organization’s security requirements. (Overby, Greiner, & Paul, 2017)
Summary
Research in IT fields has a hard time keeping up with real world applications due to the
high rate of change in the industry. This issue increases almost exponentially when one focuses
on Cloud computing security. Many research studies have taken the first step and identified
riskbased organizational concerns with Cloud computing security, and a few authors have
12
proposed novel solutions. Evidence of what organizations are doing to satisfy their risk
requirements in
Cloud computing adoption is not clear. A qualitative multiple case study-based research study
adds to the body of knowledge and further the research in the field of Cloud security, as the field
is not at the point where consensus of what are the successful frameworks and theories has
emerged. Through this study the researcher addressed the problem that researchers cannot
identify commonly understood and adopted best practice standards for small to medium sized
enterprises (SMEs) on how to specifically assess security risks relating to the Cloud. The
creation of a new framework for academic treatment of SME Cloud computing risk, and the
creation of a validated instrument that SMEs can use to assess their risk in Cloud adoption were
the reasons for this research study. A survey with a Delphi technique of industry experts is a good
step to resolving those concerns of SMEs adopting Cloud computing and is a good step to
increasing the knowledge in the academic field of Cloud security. The guiding framework of this
research study is that the risk assessment process for Cloud computing environments is
fundamentally different for SMEs than large enterprises and the primary data collection
instrument is a web survey of risk experts with a Delphi technique. The population for this
research study has constraints on security information that they can share. A qualitative case
study-based theory approach was the only way for a researcher to gather the data needed to
propose a unifying theory for SME Cloud computing risk assessment. As the state of research in
SME risk assessment tools and procedures is still in the nascent stages, case study-based theory
is the correct framework to advance the field and to create a validated instrument for SME Cloud
computing risk assessments.
13
Chapter 2: Literature Review
Introduction
This was a qualitative case study-based theory-based research project using a Delphi
technique. The researcher’s goal for this study was two-fold. The first goal was to contribute to
the academic field of research regarding SMEs adoption of Cloud computing. The second goal
was to create a validated risk instrument for use by SMEs to evaluate and assess the various risks
involved in adopting Cloud computing environments. The researcher with this research study
used several rounds of a web-based survey instrument to question a population sample of risk
subject matter experts as defined by membership in the Greater Washington D.C. chapter of
ISACA (ISACA GWDC, 2018). This research study was a direct result of the literature review
which revealed the lack of academically sound solutions for SMEs to resolve Cloud security
issues (Assante, Castro, Hamburg, & Martin, 2016; Mayadunne & Park, 2016; Rasheed, 2014).
New theory must spring from collected data, a very good fit for qualitative case study-based
theory approaches (Glaser, 2016; Mustonen-Ollila, Lehto, & Huhtinen, (2018; Wiesche, Jurisch,
Yetton, & Krcmar, 2017).
The search strategies used in researching this study included the use of Northcentral’s
online library, Google Scholar, and other online resources. The searches using Northcentral
library included all possible databases including the Institute of electrical and electronics
engineers (IEEE), the Association for computing machinery (ACM), the ProQuest computing
database, and the Gale information science and technology collection. Almost all resources are
from peer reviewed journals or conference papers that are less than five years old. Including
conference papers was a necessary decision because the general field of Cloud computing is new,
and specific sub-fields more so. Even though most conference papers are short and primarily
14
descriptive, conference papers are the leading edge of published work in a field and very
important for a field undergoing as rapid a growth as Cloud computing. As any aspect of Cloud
computing is a very young academic field, there are very few seminal articles in the field, so
none will appear in the literature review (Bayramusta & Nasir, 2016; Chang, Y., Chang, P., Xu,
Q., Ho, K., Halim, 2016; Lian, Yen, & Wang, 2014). Perhaps the closest to seminal in Cloud
research is the U.S. Department of Commerce, National Institute of Standards (NIST) special
publications regarding Cloud computing found in this research study’s list of citations (Li & Li,
2018; Mell & Grance, 2011).
This chapter includes the literature review which starts with the broad theme of
cybersecurity and Cloud computing and moves towards the more specific topic of Cloud
computing risk assessments. In this literature review, the researcher continues by addressing
several themes related to Cloud security, including themes such as improving Cloud security with
technical approaches such as encryption and new tool designs for Cloud computing
environments. The next theme is business process approaches to securing Cloud computing
environments including Security as a service (SecaaS) and service level agreements (SLAs)
including security service level agreements (SecSLAs). Cloud computing is a new field of
academic research, but there are signs of consensus among researchers on several topics (AlAnzi,
Yadav, & Soni, 2014; Rao & Selvamani, 2015).
Once the researcher presents sufficient detail regarding Cloud computing environments
and the security tools and techniques needed to secure Cloud computing environments, the
literature review will move to a SME related discussion. Research on SMEs and Cloud
computing tend to follow predictable patterns. There is an abundance of SME and Cloud
literature based on the geographical location of the SMEs (Carcary, Doherty, & Conway, 2014;
15
Carcari, Doherty, Conway, & McLaughlin, 2014; Hasheela, Smolander, & Mufeti, 2016; Kumar,
Samalia, & Verma, 2017; Qian, Baharudin, & Kanaan-Jeebna, 2016). Another popular topic
regarding SMEs and adopting Cloud computing environments focuses on the difference between
SMEs and large enterprises (Bildosola, Rio-Belver, Cilleruelo, & Garechana, 2015; Gastermann,
Stopper, Kossik, & Katalinic, 2014; Llave, 2017; Mayadunne & Park, 2016; Seethamraju, 2014).
The best research on the differences between SMEs and large enterprises adopting Cloud
computing environments, however, points to SMEs needing their own risk assessment processes
for adopting Cloud computing environments (Senarathna, Yeoh, Warren, & Salzman, 2016;
Vasiljeva, Shaikhulina, Kreslins, 2017; Wakunuma & Masika, 2017).
With the themes following the SME discussion the researcher focused on risk, risk
assessments, and Cloud computing risk assessments. The research regarding risk assessments has
a much longer history than research regarding Cloud computing adoption both in industry and in
academia (Alcantara & Melgar, 2016; Vijayakumar & Arun, 2017). Perhaps because of the well
understood and researched nature of risk assessments, there is a tendency to equate what works
with on-premise risk assessments with Cloud risk assessments, but the best of recent research
shows that solutions must change with several possible directions (Brender & Markov, 2013;
Rittle, Czerwinski, & Sullivan; Togan, 2015).
Documentation
The search terms used for this literature review generally followed the presentation of
themes. Parameters were bounded by peer reviewed journals, and 2014 or later for all searches.
The first set of searches using all available databases were Cloud, Cloud computing. Cloud
service provider, Cloud adoption. The next set of searches focused on Cloud security, improving
Cloud security, Cloud security solutions, Cloud security problems. Following searches drilled
16
down into specific types of Cloud security solutions including (Cloud OR virtual) security AND
encryption, hypervisor, network, software, or framework. Based on the previous searches, Cloud
SLAs, Cloud SecSLAs, Cloud SecaaS, were the next set of searches. Moving on to SMEs
included searches such as (SME OR small medium) Cloud, Cloud security, Cloud adoption,
Cloud security solutions. Risk based searches included Cloud risk, Cloud adoption risk, Cloud
risk assessment, SME Cloud risk solutions.
Theoretical Framework
The underlying conceptual framework for this research study is that SMEs have different
needs than large enterprises regarding Cloud computing environment risk assessments, and
academic research has not answered those needs yet (Haimes, Horowitz, Guo, Andrijcic, &
Bogdanor, 2015; Gritzalis, Iseppi, Mylonas, & Stavrou, 2018; Moncayo, & Montenegro, 2016).
This is not a giant leap into the unknown, but more of a much-needed enhancement and
specialized focus of the current business risk paradigm. Practitioners have done work on
adapting large enterprise risk assessment paradigms for Cloud computing environments but even
so, the current conceptual framework of business risk assessments does not work for SMEs
evaluating Cloud computing environments (Mahmood, Shevtshenko, Karaulova, & Otto, 2018;
Priyadarshinee, Raut, Jha, & Kamble, 2017; Wang & He, 2014). SMEs trying to use standard
risk assessment processes based on previous academic research will make incorrect decisions
regarding the risk posed by adopting Cloud computing (Kritikos & Massonet, 2016; Vasiljeva,
Shaikhulina, & Kreslins, 2017). This can lead to SMEs making poor financial decisions and
costing SMEs a competitive advantage in their field (Al-Isma'ili, Li, Shen, & He, 2016; Fernando
& Fernando, 2014). Researchers trying to use current on-premises paradigms to guide their
research efforts in SME risk assessments regarding Cloud computing adoption will not discover
17
useful validated theory. A refined conceptual framework focused on Cloud computing risks and
threats is needed both for use by SMEs in the business world and for academic researchers trying
to discover how SMEs can best use Cloud computing environments (Ali, Warren, & Mathiassen,
2017; Islam, Fenz, Weippl, & Mouratidis, 2017).
Risk assessments are a standard business process for organizations making significant
changes to their operations (Mahmood, Shevtshenko, Karaulova, & Otto, 2018; Weintraub &
Cohen, 2016). The codification of risk assessments as part of an organization’s decision-making
process have been going on since business practices started (Lanz, 2015; Szadeczky, 2016). As
new opportunities and environments including IT present themselves, organizations assess the
potential risk of changing the way the organization does business (Djuraev & Umirzakov, 2016;
Gupta, Gupta, Majumdar, & Rathore, 2016). The incredible growth of IT use in business has led
to mature and well accepted standard frameworks for addressing IT risk for large enterprises
(Atkinson, & Aucoin, 2015; Lanz, 2015; Lawson, Muriel, & Sanders, 2017).
IT risk assessments are an integral part of major changes in large enterprise’s IT
operations and there are several large-scale industry created IT risk and operations frameworks
(Calvo-Manzano, Lema-Moreta, Arcilla-Cobián, & Rubio-Sánchez, 2015; Moncayo, &
Montenegro, 2016). COBIT and ITIL as examples of industry-based frameworks, work very well
for large enterprises but are too much work for a typical SME (Devos, & Van de Ginste, 2015;
Oktadini & Surendro, 2014). SMEs have previously used ad-hoc risk assessment tools and
smaller scale solutions when evaluating IT risk (Erturk, 2017; Gastermann, Stopper, Kossik, &
Katalinic, 2014). SME risk tools are fairly well adapted to evaluating on-premises computing
risks but do not address important Cloud computing environment issues and threats (Aljawarneh,
Alawneh, & Jaradat, 2016; Lalev, 2017).
18
Cloud computing is still in its infancy and many SMEs that perform IT risk assessments
are trying to use their current on-premises IT risk assessment frameworks to evaluate whether or
not Cloud computing will save costs or provide a competitive advantage (Erturk, 2017;
Gastermann, Stopper, Kossik, & Katalinic, 2014). Their existing frameworks do not accurately
capture or describe the advantages and disadvantages of Cloud computing environments
(Goettlemann, Dahman, Gateau, Dubois, & Godart, 2014; Lai & Leu, 2015). SMEs also do not
have the capacity to adopt large enterprise risk frameworks that can create modifications for use
in evaluating Cloud computing environments (Devos, & Van de Ginste, 2015; Oktadini &
Surendro, 2014). For example, a central tenet of current SME on-premise IT risk assessments is
that an organization’s data can only be truly secure on the organization’s own IT infrastructure
(Chiregi & Navimipour, 2017). If this is a core principle of an SME’s IT security policy, then the
SME cannot use Cloud computing, as the definition of Cloud computing is that of using someone
else’s hardware. By enhancing and focusing the existing SME risk assessment framework to
properly identify Cloud computing environment risks, this research study adds to the academic
field of SME Cloud risk assessment frameworks and create a validated risk instrument that
SMEs may use.
A large number of SMEs are not IT focused and have used their existing business
processes related to risk instead of trying to adapt current large enterprise IT risk frameworks
(Haimes, Horowitz, Guo, Andrijcic, & Bogdanor, 2015; Tisdale, 2016). Some SMEs trying to
avoid using the current frameworks of on-premises IT risk assessments by following non-IT
business practices and mitigating or transferring IT risk to a third party using managed IT
solutions or managed security services providers (MSSP) (Chen & Zu, 2017; Torkura, Sukmana,
Cheng, & Meinel, 2017). Even for those SMEs that do not use IT risk assessment frameworks or
19
transfer risk by using MSSPs, Cloud computing is a very attractive alternative primarily due to
lower costs (Bildosola, Río-Belver, Cilleruelo, & Garechana,2015; Lacity & Reynolds, 2013).
The SMEs not using the dominant on-premises IT risk assessment frameworks will be able to use
this research study’s framework in a manner similar to the SMEs current business practices with
third party IT providers and MSSPs (Chen & Zu, 2017; Torkura, Sukmana, Cheng, & Meinel,
2017). These SMEs will be able to adapt to Cloud computing using the framework of this
research study by identifying important SLAs and SecSLAs that can be understood by nonIT risk
processes and business practices, thereby realizing the promise of lower costs when using Cloud
computing (Luna, Suri, Iorga, & Karmel, 2015; Oktadini & Surendro, 2014; Na & Huh, 2014).
Organizations of all sizes from all income level countries would benefit from a Cloud
environment risk assessment, although the research study focuses on high-income country-based
businesses (Assante, Castro, Hamburg, & Martin, 2016; Hussain, Hussain, Hussain, Damiani, &
Chang, 2017). Although SMEs based in all income level countries have distinct issues
(Bildosola, Rio-Belver, Cilleruelo, & Garechana, 2015; Carcary, Doherty, & Conway, 2014;
Kumar, Samalia, & Verma, 2014), every SME can face greater challenges solving these problems
as SMEs have less resources and fewer skilled employees to resolve Cloud computing risk
assessment issues than large scale enterprises (Assante, Castro, Hamburg, & Martin, 2016;
Carcary, Doherty, & Conway, 2014; Chiregi & Navimipour, 2017). A common factor for all
SMEs is that many academic solutions to properly risk assessing Cloud computing environments
require highly technical knowledge and skills that are not found in an SME’s IT staff (Hasheela,
Smolander, & Mufeti, 2016; Kumar, Samalia, & Verma, 2017) or large enterprise sized budgets
(Mayadunne & Park, 2016; Moyo & Loock, 2016). While a SME could use a good large
enterprise solution, the cost in both employee skills and financial outlay prohibit these solutions
20
in the real world (Bildosoia, Rio-Belver, Cillerueio, & Garechana, 2015; Carcary, Doherty,
Conway, & McLaughlin, 2014). This literature review illuminates how appropriate solutions for
large multi-national enterprises are rarely the correct answer for SMEs in most IT solutions, and
certainly not in Cloud security risk assessment activities.
The smaller budgets of SMEs require Cloud environment risk assessments that not only
require smaller initial cost or capital expenditures (CapEx), but also require small or controllable
continuing costs or operating expenses (OpEx). Academic solutions to Cloud environment risk
assessment needs do not always contribute to the field of SME Cloud computing environment
risk assessments. While foundational research that indicates SMEs need workable Cloud
computing environment risk assessments is present (Lacity & Reynolds, 2014; Phaphoom, Wang,
Samuel, Helmer, & Abrahamsson, 2015; Priyadarshinee, Raut, Jha, & Kamble, 2017), the next
step of addressing the need is not yet current, and the research study helps address that gap
(Trapero, Modic, Stopar, Taha, & Suri, 2017; Wang, Wood, Abdul-Rahman, & Lee, 2016).
Addressing the need of SMEs to properly assess the risk of using Cloud computing environments
is a new field of research hampered by factors unique to the SME paradigm. Due to the reduced
levels of skill and budget amounts available to SMEs (Bieber, Grivas, & Giovanoli, 2015;
Hanclova, Rozehnal, Ministr, & Tvridkova, 2015; Ndiaye, Razak, Nagayev, & Ng, 2018), the
research for SME Cloud computing risk assessments must focus on simpler ways to assess and
reduce the risk of Cloud computing adoption. This research study attempts to supply a workable
risk assessment instrument based on research that other researchers can extend and amplify going
forward.
21
Themes
Before focusing on specific themes, it is important to describe the fundamental constructs
used in this research study and in the literature review. In almost all research papers cited in this
literature review, researchers base their definition of Cloud computing on the NIST description
(Bayramusta & Nasir, 2016; Chang, Chang, Xu, Ho, & Halim, 2016; Doherty, Carcary, &
Conway, 2015; Dhingra & Rai, 2016; Tang & Liu, 2015; Zissis & Lekkas, 2012). No matter the
journal or the authors’ academic associations, the NIST definition of Cloud computing is the
standard. This makes perfect sense as the NIST definition for Cloud and Cloud security is as
close to foundational concepts as Cloud research has (Alijawarneh, Alawneh, & Jaradat, 2016;
Coppolino, D’Antonio, Mazzeo, & Romano, 2017; Demirkhan & Goul, 2011; Hallabi &
Bellaiche, 2018). While chapter one of the thesis presents most of these definitions, it is
important to define the terms here as all discussions in the cited research papers and the analysis
and synthesis in this literature review are based on a common understanding of what Cloud
computing is. The NIST definition of Cloud computing includes the following essential
characteristics:
On-demand self-service: The organization has full control of the virtual server or service
creation without intervention by the CSP (Mell & Grance, 2011).
Broad network access: The organization and its customers can reach the virtual server or
services over the Internet without proprietary tools provided by the CSP (Mell & Grance, 2011).
Resource pooling: Although the organization may be able to specify which data center the CSP
uses, the CSP uses shared resources in a multi-tenant model. The CSP allocates the resources
desired by the organization in a manner in which the CPS chooses the physical hardware and
networking systems (Mell & Grance, 2011).
22
Rapid elasticity: The organization may increase, change, or decrease the virtual server or
services in rapid and almost unlimited fashion (Mell & Grance, 2011).
Measured service: the CSP bills resource usage in units of time, and provides the organization
with the ability to monitor and control resource usage (Mell & Grance, 2011).
The NIST definition of Cloud computing include the concept of service models:
Software as a service (SaaS): The CSP provides access to an application for the organization
and its customers. The CSP is responsible for all aspects of the underlying virtual and physical
hardware with the exception of some user related settings (Mell & Grance, 2011).
Platform as a service (PaaS): PaaS is a step lower into control of the Cloud environment where
the organization is able to deploy its own applications and control most aspects of the application
without having to manage and control the underlying virtual server and network environment
(Mell & Grance, 2011).
Infrastructure as a service (IaaS): IaaS is the lowest level of control and responsibility
provided to the organization by the CSP. The organization can control the servers’ operating
systems, size, and speed, storage characteristics, networking, and accessibility by its customers to
the organization’s servers and applications (Mell & Grance, 2011).
The NIST definition of Cloud computing includes the concept of deployment models: Private
Cloud: a private Cloud is one provisioned for use by a single organization. The organization or
the CSP may manage the physical location and control over the hardware (Mell & Grance,
2011).
Community Cloud: a community Cloud gets created for use by a group of organizations sharing
similar concerns or requirements. As with a private Cloud, one of the organization or the CSP
may manage the physical location and control over the hardware (Mell & Grance, 2011).
23
Public Cloud: the CSP allows any organization to provision virtual servers or services in its
Cloud computing environment. Popular examples in North America include Amazon web
services (AWS), Google Cloud, and Microsoft Azure (Mell & Grance, 2011).
Hybrid Cloud: a combination of two or more Cloud environments tied together through
technology to allow virtual servers and services to move from one Cloud environment to another
(Mell & Grance, 2011).
Risk is an important concept to define for this literature review also. Risk as used in the
cited articles and this literature review is not as specific as the Cloud definitions. One commonly
defines risk in IT using an equation as shorthand. Risk = probability x impact / cost (Choo, 2014;
Jouini & Rabai, 2016). This literature review and the research project slightly expands this
definition to include any risk that a risk assessment tool can measure. This definition of risk
includes the risk of insufficient management buy in and the risk of the organization’s technical
staff not having the requisite Cloud knowledge and skills (Ahmed & Abraham, 2013; Luna, Suri,
Iorga, & Karmel, 2015; Shao, Cao, & Cheng, 2014).
A definition of SME as used in this literature review and the research study is important
as none of the research papers included in this literature review specify what a small enterprise or
medium enterprise is. Based on a careful reading of the research papers cited in this literature
review; the European commission definition of SMEs seems accurate. The EC definition of
SMEs is are small (15 million or less in annual revenue) to medium (60 million or less in annual
revenue) sized enterprises that are not subsidiaries of large enterprises or governments, or wholly
or partially supported by large enterprises or governments (Papdopoulos, Rikana, Alajaasko,
Salah-Eddine, Airaksinen, & Loumaranta, 2018). While Gartner may consider anything under a
billion dollars a year as a medium enterprise (Gartner, 2014), that is a very American centric
24
viewpoint and as usual Gartner is wrong, and there is no evidence that the authors of the cited
research papers relied on Gartner’s definitions of SMEs. The U.S. small business administration
(SBA) has a very complicated spreadsheet showing what types of SMEs are in a large number of
different industries (SBA, 2017). The SBA SME spreadsheet overview tab has over one thousand
entries alone and is very confusing to use, so there is no real number to gain from a hypothetical
use of the SMB spreadsheet, and there is no evidence that any of the cited research articles used
the spreadsheet when calculating enterprise sizes.
Cybersecurity
The broader field within which this research study resides is cybersecurity, or the security
of computing and IT environments. Earlier studies use the term information security or IS, but
cybersecurity has become the dominant phrase for the subject of protecting computing and IT
environments (Bojanc & Jerman-Blazic, 2008; Rahman & Choo, 2015; Tang, Wang, Yang, &
Wang, 2014).Significant cybersecurity research is only a few decades old, and as expected in
such a young field, paradigms and foundational studies are still not clear (Anand, Ryoo, & Kim,
2015; Ho, Booth, & Ocasio-Velasquez, 2017; Paxton, 2016). Rapid change is a central theme of
this literature review and a strong reason why case study-based theory and a Delphi technique are
so important for the research study. Cybersecurity is a smaller part of the information technology
(IT) field, and Cloud cybersecurity focuses on the security of Cloud based computing
environments. The IT field as a whole, is a new one compared to many business-related fields.
Cybersecurity is even newer with rapidly changing paradigms that require new research on an
ever-increasing pace (Fidler, 2017).
Cloud computing at its simplest and perhaps most disparagingly is virtual computing on
someone else’s hardware (Daylami, 2015). This simple and accurate, yet limiting definition
25
highlights the fundamental changes needed in cybersecurity. For the past thirty years,
cybersecurity has grown from a physical model to a model that is more abstract (Rabai, Jouini,
Aissa, & Mili, 2013). The first major cybersecurity paradigm of perimeter defense used physical
similes such as fences with barbed wire and armed guards, or locked server room doors and
secure server rack cages to describe the cybersecurity process. The reliance on physical examples
and thought processes based on physical security has always hampered Cybersecurity but
continued through succeeding paradigm shifts such as defense in depth, and “assume your
network is compromised” (Kichen, 2017). Cloud risk assessments suffer from the same limited
view based on physical properties (Iqbal, Kiah, Dhaghighi, Hussain, Khan, Khan, & Choo, 2016;
Mishra, Pilli, Varadharajan, & Tupakula, 2017; Rao & Selvamani, 2015). Dominant paradigms
based on physical models are obsolete when considering Cloud computing environments and so
are risk assessments for Cloud computing risk assessment. SMEs need the creation of new tools
and frameworks to stay current with Cloud security.
The rapid growth of Cloud computing is drastically changing cybersecurity (Dhingra &
Rai, 2016; Khalil, Khreishah, & Azeem, 2014; Singh, Jeong, & Park, 2016). As more SMEs
adopt Cloud computing, the industry needs to adapt to SME specific concerns, and one of the
results of the research study is a validated risk instrument that SMEs can freely use. The
cybersecurity industry already has put some effort into solutions for SMEs but SMEs need more
research (Chiregi & Navimpour, 2017; Vasiljeva, Shaikhulina, & Kreslins, 2017). In some ways
Cloud computing is similar to other fields where solutions created for large enterprises can be
pared down to SME size, such as using SaaS solutions (Assante, Castro, Hamburg, & Martin,
2016; Bildosola, Rio-Belver, Cilleruelo, & Garechana, 2015; Wang & He, 2014) or micro virtual
computing concepts such as Docker or containers (Salapura & Harper, 2018; Sun, Nanda, &
26
Jaeger, 2015). In other ways, cybersecurity has failed SMEs and Cloud computing may be a way
to avoid those mistakes (Ali, Khan, & Vasilakos, 2015; Assante, Castro, Hamburg, & Martin,
2016; Hasheela, Smolander, & Mufeti, 2016). The validated risk instrument that is one goal of
the research study will attempt to advance cybersecurity for SMEs in Cloud computing
environments and the other goal of contributing to the new academic field of Cloud computing
security will do the same.
Cloud Computing
The adoption of Cloud computing has become a business inflection point for all
organizations of any size, necessitating new research and new industry solutions for both IT and
cybersecurity (Chen, Ta-Tao, & Kazuo, 2016). Industry and the academic field are having to
react to an amazingly fast rate of change in Cloud computing industry and research topics
(Ramachandra, Iftikhar, & Khan, 2017). Although even the broader field of IT and computing in
general are very fast-moving fields of research, research in Cloud computing has to proceed at a
breakneck pace to keep up with current industry practice (Tang & Liu, 2015; Tunc & Lin, 2015).
Even with researchers working as fast as they can to describe and create theory on Cloud
computing, there are difficulties speed alone will not solve. Researchers following accepted and
respected models of academic research are falling behind in predicting and describing current
Cloud computing in the real world as it is hard to get data regarding organizations’ security
policies and procedures (Hart, 2016; Ardagna, Asal, Damiani, & Vu, 2015). Very few
organizations are willing to expose the inner workings of their IT and Cloud computing
operations (Quigley, Burns, & Stallard, 2015; Sherman et al, 2018). CSPs are even more reticent
for several reasons (Hare, 2016; Elvy, 2018). The design of survey instruments for the research
study take this into effect and avoid asking for potentially compromising information. The
27
inability to ask pertinent demographic question in the survey instruments for the research study is
another indicator of why a qualitative case study-based theory research study using a Delphi
approach with three rounds is the appropriate approach to answering the research questions.
Although research discussed under improving Cloud security theme is starting to
recommend that CSPs differentiate themselves by offering different security options (Preeti,
Runni, & Manjula, 2016; Coppolino, D’Antonio, Mazzeo, & Romano, 2017; Paxton, 2016),
there is not much evidence that CSPs are doing so (Ring, 2015; Singh, Jeong, & Park, 2016). In a
following section discussing SLAs and SecSLAs more detail on the potential security options
will be discussed but interest in these options is currently limited to smaller CSPs which have
their own drawbacks for SMEs or the solutions are not likely to be adopted (Elsayed &
Zulkernine, 2016; Furfaro, Gallo, Garro, Sacca, & Tundis, 2016; Lee, Kim, Kim, & Kim, 2017).
Potential solutions or paradigm shifts in Cloud computing security are not particularly relevant to
SMEs until SMEs understand what they need from a Cloud computing environment and what
those security risks are (Huang, Shen, Zhang, & Luo,2015; Karras, 2017; Lanz, 2015). SMEs
are not generally up to date on Cloud computing security or what potentials solutions are their
best choices (Hasheela, Smolander, & Mufeti, 2016; Hussain, Hussain, Hussain, Damiani, &
Chang, 2017), although there is some research showing that SMEs do not rank their ignorance as
a primary factor (Qian, Baharudin, & Kanaan-Jeebna, 2016; Mohabbattlab, von der Heidt, &
Mohabbattlab, 2014).
At the beginning of the Cloud computing adoption wave, many organizations and
researchers tried to evaluate Cloud computing environments based on their existing on-premises
computing security paradigms (Koualti, 2016; Barrow, Kumari, & Manjula, 2016; Paxton, 2016).
To some extent, this is still the case in academic research. Researchers have done foundational
28
work on the general topic of Cloud computing and Cloud computing adoption, and the research
on these topics has reached the point where meta analyses are possible.
Bayranmusta and Nasir present an excellent example of a literature review of two hundred and
thirty-six papers with their article titled “A fad or future of IT? A comprehensive literature review
on the Cloud computing research: (Bayranmusta & Nasir, 2016). Many other papers cover
similar ground regarding Cloud computing adoption. Some papers present qualitative survey
results (Oliveira, Thomas, & Espadanal, 2014) some comprehensive quantitative results
(Phaphoom, Wang, Samuel, Helmer, & Abrahamsson, 2015), and some papers use advanced
techniques such as neural networks (Priyadarshinee, Raut, Jha, & Gardas, 2017). The best papers
covering Cloud computing adoption approach seminal status in this very recent field by
presenting quantitative results in clear and convincing fashion (Ray, 2016; Wang, Wood,
AbdulRahman, & Lee, 2016). Some of the papers in the field that do not rise to the level of
seminal works remain interesting as their research focuses on specific parts of the business or
academic world, or particular parts of the world (Chang, Chang, Xu, Ho, & Halim, 2016; Lian,
Yen, & Wang, 2014; Musungwini, Mugoniwa, Furusa, & Rebanowako, 2016). Because many
research articles describing Cloud computing have achieved the goal of repeatable findings, and
find no significant new findings, it is time to research more specific topics in Cloud computing.
The more important of these topics are under separate theme headings in this literature review.
Cloud Security General
One of the ways researchers have been advancing the field past that of the original
researchers discussed above, is to focus on Cloud security issues, rather than just stating Cloud
security is a concern (Raza, Rashid, & Awan, 2017; Coppolino, D’Antonio, Mazzeo, & Romano,
2016; Khalil, Khreishah, & Azeem, 2014). This is a natural outgrowth of the results found by the
29
researchers cited in the general Cloud theme of this literature review. A clear and consistent result
from those studies is that Cloud security is a major concern for organizations moving to the
Cloud (El Makkaoui, Ezzati, Beni-hssane, & Motamed, 2016; Anand, Ryoo, & Kim, 2015;
Dhingra & Rai, 2016). Most researchers writing about Cloud security use standard US
Department of Commerce National Institute of Standards (NIST) Cloud and Cloud security
definitions (Ring, 2015; Khan & Al-Yasiri, 2016; Charif & Awad, 2016). Most researchers focus
on broader public Cloud security concerns (Dhingra & Rai, 2016; Khalil, Khreishah, & Azeem,
2014), although research based on particular parts of the world such as China tend to use the
private Cloud paradigm (Lian, Yen, & Wang, 2014). Even though most researchers use the same
definitions of Cloud, risk and SMEs, there are differences between researchers in what they think
is the correct approach to improving Cloud security.
Interesting differences start to appear when looking at research articles regarding general
Cloud security articles based on the journals that published the articles. Articles from more
computer science and engineering-based journals such as the Journal of Network and Computer
Applications or Annals of Telecommunications tend to focus on lower levels of the Cloud
computing stack such as hypervisor escapes or VMware based virtual computing environments
(Mishra, Pilli, Varadharajan, & Tupakula, 2017; Raza, Rashid, & Awan, 2017). Some would
argue, however, that there is a small distinction between virtual computing and Cloud computing,
with Cloud computing a subset of virtual computing (Khan & Al-Yasiri, 2016; Iqbal et al., 2016).
Cloud computing environments, especially software as a service (SaaS) Cloud computing
environments, however, have diverged so much from hypervisor-based virtualization that
researchers have to consider the topics separately (Huang & Shen, 2015; Goode, Lin, Tsai, &
Jiang, 2014). Journals not focused on computer scientists or engineers such as the Journal of
30
International Technology & Information Management, or the Journal of Business Continuity &
Emergency Planning tend to produce articles more focused on private or public Cloud computing
environments offered by Cloud Service providers (CSP) such as Microsoft Azure or Amazon web
services (AWS) (Ferdinand, 2015; Srinivasan, 2013).
Even with the different approaches based on the academic field that the researcher
focuses on, there do not seem to be many Cloud security improvements that are specific to SMEs
(Aljawarneh, Alawneh, & Jaradat, 2016; Assante, Castro, Hamburg, & Martin, 2016; Hasheela,
Smolander, & Mufeti, 2016). The technical solutions require large well-trained cybersecurity
teams that have budgets to support mathematicians or encryption subject matter experts (Feng &
Yin, 2014; Khamsemanan, Ostrovsky, & Skeith, 2016; Mengxi, Peng, & HaoMiao, 2016). The
research articles based on governance or adoption of industry frameworks such as COBIT, ITIL,
or ISO 2700 clearly do not focus on anything but large enterprises (Barton, Tejay, Lane, &
Terrell, 2016; Tisdale, 2016; Vijayakumar, & Arun, 2017). Compliance focused research articles
do not seem to scale down to SME budgets and staff either (Bahrami, Malvankar, Budhraja,
Kundu, Singhal, & Kundu, 2017; Kalaiprasath, Elankavi, & Udayakumar, 2017; Yimam &
Fernandez, 2016) even literature reviews with large numbers of articles (Halabi & Bellaiche,
2017). Improving Cloud security with SLAs and SecSLAs would seem to be the most promising
avenue for a large-scale solution working for SMEs, however, there are two main issues with this
approach. The first issue is that the currently proposed solutions are still too complicated for the
cybersecurity staff of a normal SME (Demirkan & Goul, 2011; Na & Huh, 2014; Oktadini &
Surendro, 2014) even if the cost is low (Rojas, et al, 2016). The second issue for SMEs using
31
SLAs and SecSLAs to secure their Cloud computing environments is that CSPs only modify
SLAs and SecSLAs CSPs when the customer is a very large one (Kaaniche, Mohamed, Laurent,
& Ludwig, 2017; Trapero, Modic, Stopar, Taha, & Suri, 2017).
This literature review and the research study are in partial fulfillment of the requirements
for a PhD from the school of business so the focus of this literature review is not on specific
virtual environment software or hypervisors. Given the accelerating rate of change in Cloud
computing, and the increasing adoption of public Cloud offerings in the western world, it would
not make sense to focus on specific software that will be outdated by the publication date of this
literature review. This literature review is based on English language articles and the researcher’s
focus is primarily on Western world public Cloud offerings. The American based public Cloud
providers such as AWS and Azure are the largest and fastest growing Cloud computing providers
(Darrow, 2017) and it makes sense to focus primarily on those types of offerings for this
dissertation.
Improving Cloud Security
The themes may seem to be very small slices on a single issue, but Cloud computing
security as an industry activity and an academic research field is very new and rapidly
expanding, it makes sense to separate improving Cloud security from Cloud security in general.
Many Cloud articles in the past five years are still doing important academic work by simply
defining what Cloud security is and listing potential fixes for specific issues (Bhattacharya &
Kumar, 2017; Diogenes, 2017; Ferdinand, 2015; Iqbal, Mat, Dhaghinghi, Hussein, Khan, Khan,
& Choo, 2016; Soubra & Tanriover, 2017; Srinivasan, 2013; Van Till, 2017). Cloud computing
and Cloud computing security are very new academic research fields (Bayramusta & Nasir,
2016; Chang, Chang, Xu, Ho, Halim & 2016; Lian, Yen, & Wang, 2014; Oliveira & Espanal,
32
2014; Priyaadarshinee, Raut, Jha, & Gardas, 2017). Articles baselining what Cloud computing
and Cloud computing security have been very valuable in these early days of Cloud computing
(Ab Rahman & Choo, 2015; Aich, Sen, & Dash, 2015; Gangadharan, 2017; Novkovic & Korkut,
2017; Phaphoom, Wang, Samuel, Helmer, & Abrahamsson, 2015). It is fairly simple in 2018 to
identify Cloud security as a concern for organizations that are looking to adopt Cloud computing
including SMEs (Albakri, Shanmugam, Samy, Idris, & Ahmed, 2014; Haimes, Horowitz, Guo,
Andrijcic, & Bogdanor, 2015; Vasiljeva, Shaikhulina, & Kreslins, 2017). It is not so simple to
take the next step and identify solutions that work in the business world today (Ali, Warren, &
Mathiassen, 2017; Devos & van de Ginste, 2015; Moral-Garcia, Moral-Rubio, Fernandez, &
Fernandez-Medina, 2014). Many potential solutions discussed in other themes of this literature
review may end up as the dominant paradigm in Cloud security in the next decade but they do
not help in the current business environment. If SMEs cannot find a workable solution to Cloud
security issues, the SMEs will not be secure as they adopt Cloud computing (Assante, Castro,
Hamburg, & Martin, 2016; Bildosola, Rio-Belver, Cilleruelo, & Garechana, 2015; Carcary,
Doherty, & Conway, 2015; Kumar, Samalia, & Verma, 2017; Lacity & Reynolds, 2013; Moncayo
& Montenegro, 2016; Wang & He, 2014).
This section is based on a smaller group of academic papers than most of the other
themes in this literature review. This is the simplest indication of the gap in research and the size
of the Cloud security problem, there are very few useful and even fewer accurate papers that
provide Cloud security solutions (Aljiwaneh, Alawneh, & Jaradat, 2016; Imran, Hlavacs, Haq,
Jan, Khan, & Ahmed, 2017; Islam, Fenz, Weippl, & Mouratidis, 2017). The research study plans
to fit into this section as the research goal is to determine if there is a consensus on how
organizations use a risk-based orientation to make business decisions to help secure an
organization’s Cloud computing environment. Later themes in this literature review focus on new
33
paradigm changing approaches to Cloud security that future researchers may consider
foundational ten years from now but have not yet bridged the gap between academic research
and real-life application (Cao, Moore, O’Neil, O’Sullivan, & Hanley, 2016; Carvalho, Andrade,
Castro, Coutinho, & Agoulmine, 2017; Casola, DeBenedeictis, Modic, Rak, & Villano, 2014;
Dasgupta & Pal, 2016; Torkura, Sukana, Cheng, & Meinel, 2017). Ten years may seem like a
reasonable gap between academic theory creation and industry-based applications in many fields,
but a decade in Cloud computing security is more than half the lifetime of the field itself
(Fernandes, Soares, Gomes, Freire, & Inacio, 2014; Daylami, 2015; Bunkar and Rei, 2017).
Currently available research that moves beyond discussing specific Cloud security
problems such as data storage (Paxton, 2016; Wang, Su, Dio, Wang, & Ge, 2018), moving
current physical device security paradigms to the Cloud (Khalil, Khreishah, & Azeem, 2014;
Mishra, Pilli, Varadharajan, & Tupakula, 2017), or IAM solutions (Iqbal, Mat Kiah, Dhaghighi,
Hussain, Khan, Khan, & Choo, 2016; Younis, Kifayat, & Merabti, 2014), use a variety of
methods and techniques to improve Cloud security. Solutions range from the systems
development life cycle (Aljawarneh, Alawneh, & Jaradat, 2016) to increased hypervisor security
(Coppolino, D’Antonio, Mazzeo, & Romano, 2017), to the trusted computer base (TCB)
(Navanati, Colp, Aiello, & Warfield, 2014) to a laundry list of current vulnerabilities and
solutions (Iqbal et al, 2016; Khan & Al-Yasiri, 2016), to vendor specific solutions (Diogenes,
2017).
There is a very promising encryption-based solution discussed in deeply technical
computer science and electrical engineering journals named homomorphic encryption (Bulgurcu,
Cavusoglu, & Benbasat, 2016; Feng & Xin, 2014; Khamsemanan, Ostrovsky, & Skeith, 2016;
34
Zibouh, Dalli, & Drissi, 2016) but the only business process focused article that mentions it that I
have found so far is the one by Coppolino, D’Antonio, Mazzeo, and Romano published in 2017
(Coppolino, D’Antonio Mazzeo, & Romano, 2017). Although homomorphic encryption looks
like it will allay many security concerns regarding Cloud computing adoption, it is not in use yet
and looks to be expensive and complicated, negating its use for SMEs (Dasgupta & Pal, 2016;
Feng & Xin, 2014; Souza & Puttini, 2016). Perhaps the most effective argument against
homomorphic encryption in an academic setting is that it is just another Band-Aid on IT and
Cloud security (Potey, Dhote, & Sharma, 2016; Ren, Tan, Sundaram, Wang, Ng, Chang, & Aung,
2016). Homomorphic encryption solutions allow organizations including SMEs to make the same
choices and mistakes that they do in an on-premises environment (Elhoseny, Elminir, Riad, &
Yuan, 2016; Mengxi, Peng, & Hao Miao, 2016; Wu, Chen, & Weng, 2016). Just as the research
project that this literature review is a part of does not propose a once in a generation paradigm
change to Cloud computing, homomorphic encryption lets organizations make the same security
mistakes they have been making since computing became a major business function (Bulgurcu,
Cavsogliu, & Benbasat, 2016; Potey, Dhote, & Sharma, 2016). The other major drawback to
homomorphic encryption as a topic for a thesis submitted to a business department is that it
requires very advanced mathematical skills and knowledge.
Industry-based Framework Solutions for Large Enterprises
There is a large amount of academic research in changing or transforming industry-based
framework solutions for large enterprises into solutions for SMEs (Bildosola, Rio-Belver,
Cilleruelo, & Garechana, 2015; Moyo & Loock, 2016; Seethamraju, 2014). This section of
literature review includes research papers based on industry-based frameworks such as databased
governance (Al-Ruithe, Benkhelifa, & Haneed, 2016), general governance (Barton, Tejay,
35
Lane, & Terrell, 2016; Elkhannoubi & Belaissaoui, 2016), or industry standard based governance
efforts such as ISACA’s control objectives for information and related technologies (COBIT)
(Devos & Van de Ginste, 2015). There are several complex and all-consuming industry-based
frameworks for almost all IT activities and functions including cybersecurity (Cao & Zhang,
2016; Oktadini & Surendro, 2014; Tajammul, & Parveen, 2017). These industry-based
frameworks for large enterprises have real world drawbacks for use by SMEs. These
industryframeworks are incredibly expensive in time, training, and financial terms (Haufe,
Dzombeta, Bradnis, Stantchev, & Colomo-Palacios, 2018; Kovacsne, 2018; Lanz, 2015). The
return on investment (ROI) calculation for these types of endeavors is far too small for most
SMEs (Moral-Garcia, Moral-Rubio, Fernandez, & Fernandez-Medina, 2014; Schmidt, Wood, &
Grabski, 2016).
Researchers and practitioners may be able to adapt these industry-based frameworks to
effective and useful Cloud computing security research but these industry-based frameworks are
very rigid, and do not encourage change (Tajammul, & Parveen, 2017). Industry will only accept
changes proposed by academic research when versions change for ITIL, COBIT, or ISO 2700
(Atkinson & Aucoin, 2016; IT Process Maps, 2018). Because of the structure of these
industrybased frameworks, they are very antithetical to change, in fact, the design of these
industry-based frameworks encourage elimination of any change or diversion from strict
standards wherever possible (Betz & Goldenstern, 2017; Lawson, Muriel, & Sanders, 2017).
Despite these drawbacks there does appear to be some research is currently taking place on
industry-based framework-based solutions to let organizations perform accurate and useful risk
analyses of CSPs but not particularly for SMEs (Silva, Westphall, & Westphall, 2016; Karras,
2016; Cayrici,
36
Garaga, de Oliveira, & Roudier, 2016).
Leaving aside the issue of whether or not these industry-based frameworks for large
enterprises could effectively work for SMEs, these industry-based frameworks are not able to
keep up with the massive rate of change in Cloud computing (Cram, Brohman, Gallupe, 2016;
Lohe & Legner, 2014). For example, the previously mentioned COBIT saw seven years between
COBIT 4 and COBIT 5 releases. To stay effective and timely for SME risk analysis and
assessment of Cloud computing and Cloud computing security, COBIT would have to decrease
the time between releases to seven months (Tajammul & Parveen, 2017). Additionally, within
the proposed seven-month release cycle, the industry-based frameworks would have to be
reengineered for SMEs. Unlike academic research, creators of industry-based frameworks for
large enterprises such as ITIL, COBIT, and ISO 2700 do so for-profit motives
(LeclercqVandelannoitte & Emmanuel, 2018). Printed documents, training, and certifications of
employees and organizations are very expensive to obtain and create large profits for the
certifying organization (Skeptic, 2009). SMEs are not good customers for these industry-based
frameworks as they do not have the budget for them in employee time or financial budgets
(Assante, Castro, Hamburg, & Martin, 2016Carcary, Doherty, & Conway, 2014; Senaratha, Yeoh,
Warren, & Salzman, 2016). Perhaps the only reasonable way for academic research to start with
an industry framework for large enterprises and end up with a solution for SMEs is to focus a
small part of an industry framework such as SLAs (Carvalho, Andrade, Castro, Couitinho, &
Agoulmine, 2017; Luna, Suri, Iorga, & Karmel, 2015; Na & Huh, 2014). A separate theme
discusses SLAs but find their antecedents in large enterprise agreements with vendors such as
CSPs.
37
SMEs
SMEs are present in almost every country in the world (Calvo-Manzano, Lema-Moreta,
Arcilla-Cobian, & Rubio-Sanchez, 2015) and in some countries employ more than 95% of the
total workforce (Fernando & Fernando, 2014). SMEs are responsible up to sixty per cent of all
employment, and up to forty per cent of all reported national income in emerging countries
(Ndiaye, Razak, Nagayev, & Ng, 2018). SMEs are a very large segment of the business world
and deserve a large amount of the industry-based solutions research and the academic research
for IT and Cloud security solutions (Robu, 2013; Seethamraju, 2014). While it is possible to
scale down some large enterprise solutions to SME size, as previously discussed, most cannot
(Kritikos, & Massonet, 2016; Parks & Wigand, 2014). SMEs need their own IT solutions
including Cloud security and Cloud risk assessments. These solutions will need to consider the
constraints that SMEs face such as financial and employee skill levels (Carcary, Doherty,
Conway, & McLaughlin, 2014; Hasheela, Smolander, & Mufeti, 2016). The academic research
for SME Cloud security risk assessments must accept these constraints to be useful, both in
potential industry-based solutions and for academic frameworks. There is no value in solutions
that have no chance of implementation. Even though many current SME solutions are not
probable in today’s business and industry settings, they are possible (Hussain, Hussain, Hussain,
Damiani, & Chang, 2017; Liu, Xia, Wang, & Zhong, 2017; Mohabbattalab, von der Heidt,
Mohabbattalab, 2014). As discussed previously, trying to adapt a large enterprise solution that
may cost more than the entire SME yearly budget to solve SME Cloud security problems is not
prudent (Cram, Broham, & Gallupe, 2016; Lawson, Muriel, & Sanders, 2017; Devos & Van de
Ginste, 2015). Adapting the large enterprise solutions will not yield useful results in the
incredibly fast-moving Cloud security industry or research field.
38
The same is true for academic solutions that require advanced mathematics or high levels
of skill in arcane academic fields to succeed (Potey, Dhote, & Sharma, 2016; Ren, Tan,
Sundaram, Wang, Ng, Chang, & Aung, 2016; Zibouh, Dali, & Drissi, 2016). A homomorphic
encryption solution that requires periodic changes to the cryptographic elements of the solution
are not a reasonable solution for SMEs (Feng & Xin, 2014; Khamsemanan, Ostrovsky, & Skeith,
2016; Wu, Cheng, Weng, 2016). Nor are solutions that require skill in an academic model unique
to a single or small group of papers (Deshpande et al, 2018; Kholidy, Erradi, Abelwahed, &
Baiardi, 2016; Nanavati, Colp, Aeillo, & Warfield, 2015). Unique models such as Security threats
management model (STMM) (Lai & Leu, 2015), or a data provenance model (Imran, Hlavacs,
Haq, Jan, Khan, & Ahmad, 2017), or even more common models such as using the
Software development life cycle framework to create a Software assurance reference dataset
(SARD) (Aljawarneh, Alawneh, & Jaradat, 2016) are very unlikely to be adopted by SMEs.
SMES are not just scaled down versions of large enterprises. SMEs have fundamentally
different designs and structures that require different approaches and reactions to new
technologies such as Cloud computing (Cheng & Lin, 2009; Diaz-Chao, Ficapal-Cusi, & Torrent-
Sellens, 2017; Lai, Sardakis, & Blackburn, 2015). Research attempting to discover or create
solutions for SMEs to securely adopt Cloud computing environments needs to be fundamentally
different also (Hussain, Hussain, Hussain, Damiani, & Chang, 2017; Moyo &
Loock, 2016; Wang & He, 2014). Research leading to academic and industry-based solutions for
SMEs need to focus on solutions that are closer to “turn-key” or ones SMEs can adopt without
special expertise. If an SME cannot implement a solution with its current staff, the SME is less
likely to adopt the solution (Bildosola, Río-Belver, Cilleruelo, & Garechana, 2015; Kumar,
Samalia, & Verma, 2017).
39
SMEs Local
Much of the current research on SMEs focuses on a geographically distinct group of
SMEs. While the focus on the research may be Cloud or Cloud security, the group under study is
usually in the same region of the world (Assante, Castro, Hamburg, & Martin, 2016; Bolek,
Lateckova, Romanova, Korcek, 2016; Carcary, Doherty, & Conway, 2014). After reading a large
number of research papers based on SMEs from the same state, country or continent, several
differences between regions become evident (Moyo & Loock, 2016; Senarathna, Yeoh, Warren,
& Salzaman, 2016). The differences between SMEs in one region versus another region as
regards Cloud computing adoption and Cloud security would make for a fascinating thesis by
themselves but for the purposes of this literature review and the research study it is enough to
differentiate SMEs geographically by World bank average income level groupings (Fosu, 2017).
There is an obvious and broad correlation between the SMEs in low, lower-middle, upper-middle
economies and the SMEs in high-income economies in terms of Cloud computing adoption.
SMEs in non-high-income countries do not appear to be adopting Cloud computing at a level
where they would need to do Cloud security risk assessments yet (Kumar, Samalia, & Verma,
2017; Moyo & Loock, 2016; Vasiljeva, Shaikhulina, & Kreslins, 2017). SMEs in high-income
countries, however, need Cloud security risk assessments and would find a validated risk
instrument to be a valuable commodity (Haines, Horowitz, Guo, Andrijicic, & Bogdanor, 2015;
Rahulamathavan, Rajarajan, Rana, Awan, Burnap, & Das, 2015; Sahmim & Gharsellaoui, 2017).
High income economy SMEs will be the assumed target of the research study unless otherwise
specified.
SMEs and Cloud
Cloud computing is a new and rapidly developing field of research (Khan & Al-Yasiri,
40
2016). SMEs and Cloud computing is an even newer subset of that field of research (Chiregi &
Navimipour, 2017). Even as a new subset of a new field of research there are interesting threads
developing in the field (Bildosola, Río-Belver, Cilleruelo, & Garechana, 2015; Hussain, Hussain,
Hussain, Damiani, & Chang, 2017; Mohabbattalab, von der Heidt, & Mohabbattalab, 2014).
SMEs are as competitive as large enterprises and look for potential business advantages such as
Cloud. Current research studies find that SMEs want to adopt Cloud computing for predicted
cost savings (Al-Isma'ili, Li, Shen, & He, 2016; Chatzithanasis & Michalakelis, 2018; Shkurti &
Muca, 2014), business process improvement (Chen, Ta-Tao, & Kazuo, 2016; Papachristodoulou,
Koutsaki, & Kirkos, 2017; Rocha, Gomez, Araújo, Otero, & Rodrigues, 2016), or to reach new
customer bases (Ahani, Nilashi, & Ab Rahim, 2017; George, Gyorgy, Adelina, Victor, & Janna,
2014; Stănciulescu, & Dumitrescu, 2014). SMEs’ Cloud options are different than large
enterprise options (Gholami, Daneshgar, Low, & Beydoun, 2016; Salim, Darshana, Sukanlaya,
Alarfi & Maura, 2015; Yu, Li, Li, Zhao, & Zhao, 2018). With very few exceptions in current
research (Wang, Wang, & Gordes, 2018), SMEs do not have the financial means or staff
expertise to create and adopt private or hybrid Clouds (Hsu, Ray, & Li-Hsieh, 2014; Keung &
Kwok, 2012; Michaux, Ross, & Blumenstein, 2015), nor do SMEs want to focus on Cloud
operations as a core business practice. SMEs are more likely than large enterprises to be the
customer of a community based CSP, either non-profit or for profit based (Baig, R., Freitag, F.,
Moll, A., Navarro, L., Pueyo, R., Vlassov, V., (2015; Bruque-Camara, Moyano-Fuentes, &
Maqueira-Marin, 2016), although most SMEs will use a public Cloud offering (Buss, 2013;
Cong & Aiqing, 2014). Large enterprises are more likely to adopt a private Cloud or leverage
their large enterprise size to be a valued customer of one of the largest CSPs such as AWS,
Azure, or Google Cloud (Chalita, Zalila, Gourdin, & Merle, 2018; Persico, Botta, Marchetta,
Montieri, & Pescape, 2017; Vizard, 2016). SMEs cannot offer the scale of purchasing to receive
41
significant discounts from the large CSPs and are more likely to see value in a community Cloud
that understands the SMEs core business practices, or a smaller CSP that specializes in the
SMEs’ core business practices (Huang, et al, 2015; Wang & He, 2014).
SMEs and IaaS
A number of research studies show that SMEs should be more likely to adopt SaaS CSP
offerings than PaaS or IaaS CSP offerings but researchers need to do more work. One of the
issues with concluding that SMEs should use SaaS Cloud computing options is that the research
does not show that SMEs actually are using SaaS more than IaaS and PaaS (Achargui & Zaouia,
2017; Hasheela, Smolander, & Mufeti, 2016). While the arguments made by the researchers are
imminently logical, the same research does not show that they have not yet persuaded SMEs
with those arguments. The research study’s survey instruments and the validated risk instrument
associated with the research include SaaS Cloud computing.
There is research describing SMEs use or lack of use of PaaS Cloud computing
environments (Bassiliades, Symeonidis, Meditskos, Kontopoulos, Gouvas, & Vlahavas, 2017;
Ionela, 2014). The current research regarding SMEs and PaaS does not reach a reproducible
conclusion and the research tends to focus on PaaS offerings of very large business application
software suites (Bassiliades, Symeonidis, Meditskos, Kontopoulos, Gouvas, & Vlahavas, 2017;
Kritikos, Kirkham, Kryza, & Massonet, 2015; Papachristodoulou, Koutsaki, & Kirkos, 2017).
The recent research studies discussing high-income country-based SMEs and PaaS Cloud
computing environments tend to focus on the SMEs adoption and use of the large software
programs such as enterprise resource planning programs (ERP) or huge customer relationship
management programs (CRM) (Calvo-Manzano, Lema-Moreta, Arcilla-Cobián, &
RubioSánchez, 2015; Rocha, Gomez, Araújo, Otero, & Rodrigues, 2016). Research based on
42
lower income-based country SMEs and PaaS Cloud computing environment offerings tend to
focus on the smaller SMEs and their adoption of the more individual customer-based PaaS Cloud
environments such as Google Gmail or Microsoft Office 365 (Chatzithanasis & Michalakelis,
2018; Hasheela, Smolander, & Mufeti, 2016).
Some research shows that SMEs tend to adopt Cloud paradigms that the SME’s current
staff is comfortable using (Assante, Castro, Hamburg, & Martin, 2016; Carcary, Doherty,
Conway, & McLaughlin, 2014). In many cases the simplest Cloud service to adjust to when first
adopting Cloud computing, is that of IaaS (Cong &Alquing, 2014; Fernando & Fernando, 2014;
Keung & Kwok, 2012). An SME’s IT staff can perform the same job duties on a virtual server in
an IaaS environment that they did on an on-premise computer server. While the IT staff will have
to become conversant with the CSP’s IaaS server provisioning process, all major CSPs allow one
to create a server and network online through a web page. The SME’s IT staff can also create and
destroy IaaS servers quickly and cheaply to learn the CSP’s process (Chalita, Zalila,
Gourdin, & Merle, 2018; Persico, Botta, Marchetta, Montieri, & Pescapé, 2017; Vizard, 2016).
The SME’s will need to learn the most cost-effective way to utilize the CSP’s IaaS environment,
but that holds true for the CSP’s PaaS and SaaS environments.
IaaS Cloud computing environments are a good choice for SMEs in several scenarios. If
an SME is ready to make a wholesale move to the Cloud, perhaps as part of the initial IT setup
and configuration, moving to an IaaS environment can offer a base virtual environment where the
SME’s IT team can setup its environment any way it deems best (Chalita, Zalila, Gourdin, &
Merle, 2018; Vizard, 2016). If an SME is moving an existing server room or data center into a
public or private Cloud, and the SME can outsource the forklift portion of adopting a Cloud
computing environment, the SME’s IT staff need to learn a smaller set of Cloud computing
43
specific skills and tasks (Fahmideh & Beydoun, 2018). IaaS Cloud computing environments are
the best choice for SMEs that have to move into a Cloud computing environment quickly
(AlIsma'ili, Li, Shen, & He, 2016; Baig, Freitag, Moll, Navarro, Pueyo, Vlassov, 2015).
IaaS Cloud environments are attractive to SMEs in other scenarios too. If the SME
decides on a gradual move to the Cloud with a policy of all new servers created in a CSP hosted
environment, the SME’s IT staff can gradually learn the skills needed server by server
(Senarathna, Wilkin, Warren, Yeoh, & Salzman, 2018). A gradual move to a CSP environment
can coincide with other business processes within the SME such as amortization and cost
writeoffs for servers and server room equipment, or technology life-cycle events such as aging
out of a specific server model (Gupta & Saini, 2017; Rocha, Gomez, Araújo, Otero, &
Rodrigues, 2016). A gradual move based on business processes has the additional benefit of
stronger buy-in from other business units within the SME for continued Cloud operations
(Kouatli, 2016; Raza, Rashid, & Awan, 2017).
PaaS and SaaS CSP options can be strong options for SMEs in various scenarios. Very
small businesses, may only need a limited amount of IT perhaps one or two applications such as
email and document sharing and storage (Hasheela, Smolander, & Mufeti, 2016; Moyo & Loock,
2016). If a small enterprise only needs to use applications, not to build and change them, SaaS or
PaaS would be an appropriate choice (Musungwini, Mugoniwa, Furusa, & Rebanowako, 2016).
If a small enterprise’s IT needs do reach the level of individual servers or a server room, the
SME may not IT staff with competencies much higher than that of an IT Help-Desk. IF the SME
does not currently manage on premise servers, PaaS or SaaS would be a logical choice for a
Cloud computing environment (Bassiliades, Symeonidis, Meditskos, Kontopoulos, Gouvas, &
Vlahavas, 2017; Ionela, 2014). As the research study focuses on high-income SMEs that need a
44
validated risk instrument for adopting Cloud computing solutions securely, single customerbased
SaaS or PaaS solutions will not get much coverage.
SME Cloud Security
Just as in general Cloud security research, SME focused Cloud security research has
reached the point where researchers have done the general descriptive baselining of what a
current Cloud computing environment is (Kumar, Samalia, & Verma, 2017; Lacity & Reynolds,
2013), how Cloud security is different than on premise IT security (Liu, Xia, Wang, Zhong,
2017), and why Cloud security is important for SMEs (Mohabbattalab, von der Heidt, &
Mohabbattalab, 2014). Even research that does not start with the focus on SMEs can be very
informative when describing Cloud computing environments and the security needs of SMEs for
Cloud adoption (Shaikh & Sasikumar, 2015; Sun, Nanda, & Jaeger, 2015). Even though parts of
this literature review make large the differences between SMEs and large enterprises, at a basic
level, a Cloud computing environment has a basic structure that is the same for any size company
(Phaphoom, Wang, Samuel, Helmer, & Abrahamsson, 2015; Ray 2016). So too, Cloud
computing security starts the same for an organization whether they have one employee or fifty
thousand employees.
Differences between Large Enterprises and SMEs
The differences between SME on-premise IT security and potential Cloud security can
look fairly similar to the same comparison for large enterprises (Diogenes, 2017; Hussain,
Mehwish, Atif, Imran, & Raja Khurram, 2017). SMEs tend to have very different on-premises IT
security needs, budgets, and practices than large enterprises, but at the basic level, Cloud
computing is using someone else’s hardware (Daylami, 2015). This tends to be truer for SMEs
than large enterprises as financial budgets play a large role in whether or not an organization
45
decides to create its own Cloud environment such as a private Cloud or a hybrid Cloud
environment leading to more use of public Cloud offerings by SMEs (Shkurti, & Muça, 2014).
The lack of Cloud expertise held by SME’s IT staff would also tend to negate the possibilities of
an SME creating its own Cloud baseline. When a researcher starts to investigate actual business
practices and the details in Cloud adoption and Cloud security, SMEs start to differentiate
themselves from large organizations (Chatzithanasis, & Michalakelis, 2018; Rocha, Gomez,
Araújo, Otero, & Rodrigues, 2016).
Aside from decision making influences such as budget and IT staff expertise, the
importance of SME Cloud security can look similar to what a large enterprise considers
important in Cloud security when focusing on the details. In general, if a large enterprise in a
specific industry faces a security threat when adopting Cloud computing environments, SMEs
face similar concerns, just on a smaller scale. In specific cases, large enterprises do have greater
security concerns and concomitant practices to allaying those security concerns (Bahrami,
Malvankar, Budhraja, Kundu, Singhal, & Kundu, 2017; Yimam & Fernandez, 2016). Large
enterprises have access to solutions that SMEs do not such as creating new Cloud security teams,
or hiring CSP based security subject matter experts. As with differences between on-premises
and Cloud security between large enterprises and SMEs, the differences between SMEs and large
enterprises regarding Cloud computing security start to gain prominence when a researcher starts
to focus on details. Focusing on these and other details is a basic part of the case study-based
theory coding process and played an integral part of the research study.
As discussed, Cloud computing security for SMEs starts at a similar place to Cloud
security for larger enterprises. Cloud computing involves using someone else’s hardware and the
corresponding loss of control that giving up physical security involves (Daylami, 2015). While
46
SMEs have similar security concerns and all organizations would like to keep confidential
information secret, the size of an organization affects the way in which SMEs secure their data.
SME focused academic research solutions tend to be smaller scale and less expensive (Bildosola,
Río-Belver, Cilleruelo, & Garechana, 2015; Gastermann, Stopper, Kossik, & Katalinic, 2014
Lacity & Reynolds, 2013; Senarathna, Yeoh, Warren, & Salzman, 2016). Some current SME
Cloud computing security solutions are just lists of threats and how to remediate the threats,
which although very cost effective, are not forward-looking solutions frameworks (Lalev, 2017;
Preeti, Runni, & Manjula, 2016). Other current SME Cloud computing security solutions require
SMEs to create new teams or business processes (Haimes, Horowitz, Guo, Andrijcic, &
Bogdanor, 2015; Lai & Leu, 2015). The best of current academic SME solutions to Cloud
security do not create new processes or tools for SMEs to learn but instead help SMEs to
simplify their treatment of data and to reduce the SME’s attack surface (Carcary, Doherty,
Conway, & McLaughlin, 2014; Ertuk, 2017; Gritzalis, Iseppi, Mylonas, & Stavrou, 2018).
SME Using Cloud to Reduce Costs
SMEs are less likely to embrace the costs of creating and maintaining server rooms with
dedicated power and cooling than large enterprises (Tso, Jouet, & Pezaros, 2016). SMEs are
more likely to be based in one physical location making redundancy and failover more difficult
for the organization’s pre-Cloud IT infrastructure (Lent, 2016). As such, Cloud computing may
look more attractive for an SME than a large enterprise when the viewpoint is financial or
business process related (Bildosoia, Rio-Belver, Cillerueio, & Garechana, 2015; Carcary,
Doherty, Conway, & McLaughlin, 2014). In terms of a Cloud security solution, SMEs may be
able to bridge some of the gap between them and large enterprises in that SME Cloud security
solutions can include multi-Cloud or fully redundant solutions without major increases in cost or
47
effort (Ertuk, 2017; Salim, Darshana, Sukanlaya, Alarfi & Maura, 2015; Wang & He, 2014). An
SME that can adopt business processes or solutions normally restricted to large enterprises can
gain a competitive advantage (Hsu, Ray, & Li-Hsieh, 2014). Cloud computing can be a tool for
SMEs to adopt some large enterprise IT standards such as full redundancy and auto scaling of
organizational resources to customer demand (Buss, 2013; Huang, et al, 2015; Michaux, Ross, &
Blumenstein, 2015).
There are many ways for an organization to adopt Cloud computing and many different
ways to manage the risk of Cloud computing adoption. The differences between the solutions,
including security solutions can be much more than a result of “throwing more money at it” that
can dismissively explain the differences between SMEs and large enterprises when discussing
on-premises IT security solutions. SMEs may be able to adopt solutions such as multi-Cloud
(Zibouh, Dalli, Drissi, 2016, Cloud access security broker (CASB) (Paxton, 2016), or automation
of security controls (Tunc, et al, 2015) that if based on-premises would be solely the provenance
of large enterprises. These possible Cloud security solutions are still outside of the main stream
for SMEs, however, and SMEs need a way to assess the risk of using these or more standard
solutions. The research study is a start to providing SMEs a way to assess the risks of adoption a
Cloud computing solution, even if the solutions is one that the SME would never consider in an
on-premises environment (Albakri, Shanmugam, Samy, Idris, & Ahmed, 2014; Ngo.
Demchenko, & de Laat, 2016; Younis, Kifayat, & Merabti, 2014). The promise of gaining an
edge on their competition should have SMEs looking at the feasibility of these new solutions.
One important promise of Cloud computing for SMEs is that rather than be forced to
decide from a scaled down, reduced cost version of a large enterprise solution or a simpler, less
secure solution, SMEs will be able to choose from a larger selection of Cloud security solutions
48
if it is easier for SMEs to assess the risk of each solution. Due to previously discussed dual
constraints of smaller financial budgets and lower skill levels of IT staff, SMEs tend to
contemplate different priorities in Cloud computing risk calculations. If SMEs could reasonably
assess the risk of using new Cloud computing security solutions, SMEs could be much more
secure in the Cloud than they currently are on-premises (Chen, Ta-Tao, & Kazuo, 2016;
Seethamraju, 2014). SMEs cannot realize the great promise of Cloud computing adoption SMEs
if the SMEs cannot properly asses the risk of using a Cloud computing environment.
Cloud Security as an Improvement
An interesting difference between SMEs and large enterprises shows up in some SME
based research papers that indicates that for many SMEs, basic Cloud security is an improvement
over the SMEs existing IT security (Lacity & Reynolds, 2013; Mohabbattalab, von der Heidt, &
Mohabbattalab, 2014). The SMEs where basic CSP provided security is better than the SME in
house security, are most likely the smaller SMEs discussed earlier that have limited IT needs and
limited IT staffs (Mayadunne & Park, 2016; Senarathna, Yeoh, Warren, & Salzman, 2016; Wang
& He, 2014). Some SMEs have very limited in IT security. For those SMEs, the adoption of
Cloud computing environments is an improvement in the SMEs security posture. These SMEs
are among those that would find the greatest help from a validated risk instrument. An inadequate
cybersecurity budget almost certainly means, at the very least, the staff have little free time to
research Cloud security options.
While public CSPs have many whitepapers discussing their security and the risk
assessment attestations they have (Chalita, Zalila, Gourdin, & Merle, 2018; Persico, Botta,
Marchetta, Montieri, & Pescapé, 2017; Vizard, 2016), the documents and attestations do not
apply to the CSP’s customer’s security. Even if the SME’s cybersecurity team has been able to
49
read the CSPs explanations of how their Cloud security offerings work, the SME still needs to
work through how each solution fits the organization’s specific needs. Having said that, the
current academic research in SME Cloud security is moving towards a consensus that SMEs can
be more secure at a lower cost in the Cloud than on-premises (Al-Isma'ili, Li, Shen, & He, 2016;
Bassiliades, Symeonidis, Meditskos, Kontopoulos, Gouvas, & Vlahavas, 2017; Famideh &
Beydoun, 2018; Shkurti, & Muça, 2014). SMEs still need a way to ensure that the solution they
pick make the SME more secure, and the research study produced a validated risk instrument that
will help SMEs do so.
Risk
As discussed earlier in this literature review, professionals commonly define risk in IT
using an equation as shorthand. Risk = probability x impact / cost (Choo, 2014; Jouini & Rabai,
2016). Researchers have done good academic research on the risk involved with Cloud
computing adoption (Jouini & Rabai, 2016; Vijayakumar, & Arun, 2017). Researchers have
published less regarding the risk SMEs take in adopting Cloud computing and how SMEs
evaluate the risk (Assante, Castro, Hamburg, & Martin, 2016; Hussain, Hussain, Hussain,
Damiani, & Chang, 2017). The research study helps to fill the gap in academic research about
SME risk assessment processes when adopting Cloud computing, and the research study
generated a validated instrument that SMEs can use during a Cloud risk assessment. This
literature review followed the same general pattern for researching risk as the sections for SMEs
and Cloud security; starting broadly and narrowing down to the final topic.
Risk Descriptive
The first section of the literature review research on SME Cloud computing risk
assessments is the general field describing risk relating to Cloud computing. There is adequate
50
research on broad questions such as the differences between on-premises IT risk and Cloud
computing environment risks, with the simplest answer being that risk is different in the Cloud
(Li & Li, 2018; Rittle, Czerwinski, & Sullivan, 2016; Shackleford, 2016). More nuanced
analyses of how Cloud security presents different risks is also represented in the literature, from
highly detailed quantitative models (Hu, Chen, & We, 2016; Jouini & Rabai, 2016; Tanimoto et
al, 2014) to qualitative descriptive research papers (Iqbal et al, 2016; Khalil, Khreishah, &
Azeem, 2014; Hussain, Mehwish, Atif, Imran, & Raja Khurram, 2017) ) to presentations of
controls and responses that should be taken to ameliorate Cloud computing risk (Khan & Al-
Yasiri, 2016; Preeti, Runni, & Manjula, 2016).
Unfortunately, due to the newness of the field, many articles on Cloud computing risk are
more descriptive based rather than discovery focused (Mishra, Pilli, Varadharajan, & Tupakula,
2017; Singh, Jeong, & Park, 2016). While many of these research papers do a very good job of
describing Cloud computing risk at a high level (Choi & Lambert, 2017; Shackleford, 2016) and
some can be very informative at a lower level of Cloud risk (Casola, De Benedictis, Erascu,
Modic, & Rak, 2017; Lai & Leu, 2015), very few research papers reach the level that would have
other researchers want to expand or extend the research (Masky, Young, & Choe, 2015; Ngo,
Demchenko, & de Laat, 2016). It is logical that academic researchers have to fully describe a
new problem, environment, process, or framework before the important work of discovering how
to improve it. One cannot expect quality research from the academic field regarding Cloud
computing security risk until that risk is fully detailed, but the research study and this literature
review took steps in that direction.
The incredible rate of change in the Cloud computing industry is surprising even by IT
standards (Bayramusta & Nasir, 2016) The value of properly researched and peer reviewed
51
articles based on the details of specific risks involved in adopting Cloud computing such as
hypervisor attacks (Nanavati, Colp, Aeillo, & Warfield, 2014), or other specific CSP weaknesses
(Deshpande, et al. 2018) is minimal as the industry will have reacted before the research paper is
published (Kurpjuhn, 2015; Preeti, Runni, & Manjula, 2016). The current research available does
a better job describing the risks involved with using a Cloud computing IaaS environment than a
PaaS or SaaS Cloud computing environment (Gritzalis, Iseppi, Mylonas, & Stavrou, 2018; Wang
& He, 2014). This is predictable as an IaaS environment is closest to existing on-premises
environments and existing research models and paradigms for computing security. While some
researchers actively focus on risk in PaaS and SaaS Cloud computing environments (Gupta,
Gupta, Majumdar, & Rathore, 2016; Weintraub & Cohen, 2016) the ratio seems to be off. It is
reasonable to expect that just as on-premises computing is being supplanted by Cloud computing
for all the reasons discussed in this literature review, so too will be IaaS with PaaS, SaaS, and
new paradigms that have not been created yet (Kritikos, Kirkham, Kryza, & Massonet, 2015;
Priyadarshinee, Raut, Jha, & Kamble, 2017). As the industry and CSPs move to more dynamic
and complicated computing paradigms and environments such as containers (Bahrami,
Malvankar, Budhraja, Kundu, Singhal, & Kundu, 2017), micro-services (Sun, Nanda, & Jaeger,
2015), compute as a service (Qiang, 2015), security as a service (SecaaS) (Torkura, Sukmana,
Cheng, & Meinel, 2017), and eventually everything as a service (Sung, Zhang, Higgins, & Choe,
2016), academic research focused on just describing old models of Cloud risk will not be useful.
SME Risk Assessment
Organizations are rapidly moving to the Cloud (Khan & Al-Yasiri, 2016). The vast
majority of medium to large organizations have policies and procedures regarding adoption and
use of IT such as Cloud computing (Madria, 2016; Shackleford, 2016). The core of the research
project is discovering how organizations are approving the use of Cloud computing environments
52
based on a risk paradigm. At a high level, organizations can use existing risk frameworks such as
ISO2700, or COBIT (Devos & Van de Ginste, 2015), alter their current riskbased procedures or
alter the organization’s Cloud computing environments to match the organization’s current risk
requirements.
SMEs are not likely to use large industry-based IT control frameworks such as ITIL,
COBIT, or ISO2700 because of the cost of implementing the industry frameworks (Barton, Tejay,
Lane, & Terrell, 2016; Tisdale, 2016; Vijayakumar, & Arun, 2017). As discussed previously, the
cost of training staff and implementing such frameworks can be higher than an SME’s entire IT
budget (Atkinson & Aucoin, 2016; IT Process Maps, 2018). Perhaps the true value of such
frameworks is the ability to standardize IT processes across a global company and across many
business units (Cao & Zhang, 2016; Oktadini & Surendro, 2014; Tajammul, & Parveen, 2017).
Such standardization is not a business driver for SMEs and is usually a goal of mature large
enterprises.
SMEs are likely to alter their current risk procedures when adopting Cloud computing.
The alteration process is not that of a large enterprise, however. A large enterprise will have
entire teams dedicated to IT risk assessments and may even have separate teams based on the
type of risk (Zong-you, Wen-long, Yan-an, & Hai-too, 2017). Global enterprises may have
different IT risk assessment teams dedicated to applications, infrastructure, and new software
acquisitions (Damenu & Balakrishna, 2015). Large enterprises may reasonably treat a new Cloud
computing environment as any one of those types of risk assessment types and only require
minor alterations to the large enterprises business processes to finish a Cloud computing risk
assessment. SMEs have no such separate risk teams, and may have no internal audit or risk teams
whatsoever (Mahmood, Shevtshenko, Karaulova, & Otto, 2018). SMEs are more likely to
53
contract outside audit and risk firms, and only when required by law for financial audits and
other matters (Gupta, Misra, Singh, Kumar, & Kumar, 2017). SMEs may use consultants for a
Cloud computing risk assessment but would save money by using something similar to the
validated risk instrument that is an output of the research study.
As with altering their current risk assessment procedures, large enterprises are most likely
to require constraints and limitations on a Cloud computing environment before approving
moving to the Cloud. Large enterprises have the resources, both financially and in qualified staff
to create a private Cloud limited to a single organization if they wish (Gupta, Misra, Singh,
Kumar, & Kumar, 2017). More commonly, large organizations will use their greater resources to
design a Cloud environment to their specifications that will pass an internal risk assessment
(Chang & Ramachandran, 2016). A very simple example is that a large organization can separate
confidential and non-confidential data to prevent the storage of data in the Cloud. A large
organization may also leverage the size of their Cloud deployment to secure changes and
discounts from the CSP (Gupta, Misra, Singh, Kumar, & Kumar, 2017). These are all examples
of changes to a Cloud environment that SMEs are not able to do. SMEs are far more likely to
have to accept what a CSP offers as the SME has no leverage with the CSP to enact changes.
One choice SMEs do have in their favor is the choice of CSP or combinations of CSPs. A
validated risk instrument that will allow SMEs to make effective choices between various public
CSPs will be a very useful tool.
Cloud Risk Solutions
A thorough review and understanding of current risk assessment and acceptance policies
and procedures is critical to this research project. This section of the literature review focuses on
how academic research is writing about Cloud computing risk. Many authors have done good
54
work in identifying Cloud computing risk factors (Jouini & Rabai, 2016; Hu, Chen, & We, 2016;
Alali & Yeh, 2012). One can see many challenges found in on-premises computing risk
assessments also identified in Cloud computing environments along with many risk factors that
are distinct to the Cloud (Cayirci, Garaga, de Oliveira, & Roudier, 2016; Madria, 2016). From a
focus on those specific threats and corresponding security controls (Sen & Madria, 2014;
Albakri, Shanmugam, Samy, Idris, & Ahmed, 2014; Ramachandran & Chang, 2016) to higher
level risk analysis focuses (Brender & Markov, 2013; Shackleford, 2016; Gupta, Gupta,
Majumdar, & Rathore, 2016), there is a wide range of published research.
Some of the proposed solutions are interesting, including a new access control model for
Cloud computing by Younis, Kifayat, and Merabti that incorporates features of mandatory access
control models (MAC), role-based access control models (RBAC), discretionary access control
models (DAC), and attribute-based access control models (ABAC) to create a new model of
riskbased access control (RBAC) (Younis, Kifayat, & Merabti, 2014). A focus on business
process modeling notation (BPMN) also looks promising (Ramachandran & Chang, 2016). There
are proposals to use fuzzy decision theory (de Gusmao, e Silva, Silva, Poleto, & Costa, 2015),
and extensible access control markup language (XACML) (dos Santos, Marinho, Schmitt,
Westphall,
& Wesphall, 2016) as the basis of solutions to Cloud computing risk.
SME Cloud Risk Solutions
Unfortunately, none of these solutions are a good fit for SMEs. Based on previously
discussed constraints of financial and staff skill constraints, complicated additional skill needed
processes will not help SMEs properly assess the risk involved in adopting Cloud computing.
One of the main attractions of the Cloud for SMEs is that the promise for SMEs that they will
55
have to do less work and spend less money than with on-premises solutions (Bayramusta, &
Nasir, 2016; Lalev, 2917; Raza, Rashid, & Awan, 2017). Adding very complicated and complex
controls based on RBAC or BPMN or fuzzy decision theory is a non-starter for most SMEs
(Ramachandran & Chang, 2016). One of the promises of Cloud computing for SMEs is that
different paradigms and solutions will emerge in the high rate of change within the Cloud
computing field. A successful solution for SMEs is one that SMEs can easily understand and
adopt. At the present time, this means that the solution or paradigm has to be based on a currently
understood model such as the classic equation of risk, risk = probability x impact / cost (Choo,
2014; Jouini & Rabai, 2016).
Research is lacking on proposed more traditional risk assessment instruments for Cloud
computing but portions of the research papers that are public has some very good ideas and
potential avenues to research (Gritzalis, Iseppi, Mylonas, & Stavrou, 2018). Building a risk
instrument based upon a simple to understand industry tool such as the common vulnerability
scoring system (CVSS) has promise for SMEs but real-world examples are lacking (Maghrabi,
Pfluegel, & Noorji, 2016). Several groups of authors are presenting research papers that are
attempting to provide validated risk instruments similar to the research paper, including
RAClouds based on ISO27001 (Silva, Westphall, & Westphall, 2016) and risk instruments based
on the ISO 31000 risk management framework (Viehmann, 2014) but the results are not easy to
use.
Some researchers are investigating making Cloud risk assessments more accessible to
SMEs but solutions are not complete (Damenu & Balakrishna, 2015; Djuraev & Umirzakov,
2016; El-Attar, Awad, & Omara, 2016). Other approaches to understanding and properly
assessing Cloud computing risk get complicated very quickly even though they propose
56
interesting solutions. If research concepts such as reducing Cloud computing risk assessments to
simple business process evaluations (Goettlemann, Dalman, Gateau, Dubois, & Godart, 2014), or
Cloud risk assessments based on Markov models (Karras, 2017); or Cloud risk assessments
based on vertical stacking of groups of SMEs (Mahmood, Shevtshenko, Karaulova, & Otto,
2018) come to fruition, perhaps validated risk instruments will not be as important as they are
today. More optimistic researchers are positing theories based on getting CSPs to change and
offer more services such as Security SLAs or more access to the CSPs internal workings
(Rasheed, 2014; Razumnikov, Zakharova, & Kremneva, 2014; Tang, Wang, Yang, & Wang,
2014; Weintraub & Cohen, 2016). The research study provides a validated risk instrument that
can help SMEs assess the risk of adopting Cloud computing in a simple and rational way that
will work without proposing radical changes in the way CSPs conduct business. While large
enterprises can force changes on CSPs due to the large amounts of money they spend, SMEs do
not have that leverage.
Summary
The theoretical framework discussed in this literature review is that SMEs have different
needs than large enterprises regarding Cloud computing environment risk assessments, and
academic research has not answered those needs yet (Haimes, Horowitz, Guo, Andrijcic, &
Bogdanor, 2015; Gritzalis, Iseppi, Mylonas, & Stavrou, 2018; Moncayo, & Montenegro, 2016).
The process to researching potential solutions for SME Cloud computing risk assessments started
with broad searches involving cybersecurity (Anand, Ryoo, & Kim, 2015; Ho, Booth, &
OcasioVelasquez, 2017; Paxton, 2016), Cloud computing (Chen, Ta-Tao, & Kazuo, 2016;
Ramachandra, Iftikhar, & Khan, 2017), and Cloud security (Coppolino, D’Antonio, Mazzeo, &
Romano, 2017; Ring, 2015; Singh, Jeong, & Park, 2016). There is research that investigates
57
industry-based framework solutions for large enterprises as potential solutions but they were
found not to be appropriate for SMEs (Al-Ruithe, Benkhelifa, & Haneed, 2016; Bildosola,
RioBelver, Cilleruelo, & Garechana, 2015; Elkhannoubi & Belaissaoui, 2016; Moyo & Loock,
2016; Seethamraju, 2014). SMEs have their own requirements and constraints for most IT
solutions (Gholami, Daneshgar, Low, & Beydoun, 2016; Salim, Darshana, Sukanlaya, Alarfi &
Maura, 2015; Yu, Li, Li, Zhao, & Zhao, 2018) and for adopting Cloud computing such as cost
savings (Al-Isma'ili, Li, Shen, & He, 2016; Chatzithanasis & Michalakelis, 2018; Shkurti &
Muca, 2014) or business process improvements (Chen, Ta-Tao, & Kazuo, 2016;
Papachristodoulou, Koutsaki, & Kirkos, 2017; Rocha, Gomez, Araújo, Otero, & Rodrigues,
2016). SME specific Cloud computing risk assessments that do not use old and outdated
onpremises paradigms are not evident in the literature (Baig, R., Freitag, F., Moll, A., Navarro,
L.,
Pueyo, R., Vlassov, V., (2015; Bruque-Camara, Moyano-Fuentes, & Maqueira-Marin, 2016;
Buss, 2013; Cong & Aiqing, 2014). The research study creates a validated risk assessment
instrument, and advances the academic field of SME Cloud computing which is lacking in
research focused solely on SME Cloud computing risk assessments (Aljawarneh, Alawneh, &
Jaradat, 2016; Assante, Castro, Hamburg, & Martin, 2016; Feng & Yin, 2014; Hasheela,
Smolander, & Mufeti, 2016).
58
Chapter 3: Research Method
The problem the researcher addressed with this study is that there is no commonly
understood and adopted best practice standard for small to medium sized enterprises (SMEs) on
how to specifically assess security risks relating to the Cloud. The purpose of this qualitative case
study research study was to discover an underlying framework for research in SME risk analysis
for Cloud computing and to create a validated instrument that SMEs can use to assess their risk
in Cloud adoption. In this chapter, the researcher presents the research methodology and design
in detail, including population, sample, instrumentation, data collection and analysis,
assumptions, and limitations. Collecting data using a Delphi technique with three rounds
provided the researcher with enough information from multiple case studies regarding SME
Cloud computing risk assessments. Using a Delphi technique is more successful if the sample is
from a population of subject matter experts. Using subject matter experts informed the
limitations, assumptions, and ethical practices in this research study.
SMEs have a different relationship with risk in general (Assante, Castro, Hamburg, &
Martin, 2016) and Cloud adoption risk in particular (Lacity & Reynolds, 2013; Qian, Baharudin,
& Kanaan-Jeebna, 2016; Phaphoom, Wang, Samuel, Helmer, & Abrahamsson, P. 2015). While
many SMEs see Cloud adoption as an avenue to increase their overall security posture
(Bildosola, Río-Belver, Cilleruelo, & Garechana, 2015; Mohabbattalab, von der Heidt, &
Mohabbattalab, 2014; Wang & He, 2014), they do not have the skilled staff or requisite expertise
to create the business and IT processes and procedures to ensure a more secure result (Carcary,
M., Doherty, Conway, & McLaughlin, 2014; Hasheela, Smolander, & Mufeti, 2016). It is
standard practice for medium to large enterprises to use risk assessments before adopting new
computing environments and SMEs should follow the same process (Cayirci, Garaga, Santana de
59
Oliveira, & Roudier, 2016; Jouini & Rabai, 2016). SMEs, however, cannot generally create their
own security procedures and need a process or validated instrument such as a risk assessment to
determine if they should move to the Cloud (Bildosola, Rio-Belver, Cilleruelo, & Garechana,
2015; Carcary, Doherty, & Conway, 2014; Hasheela, Smolander, & Mufeti, 2016). Current
research does not provide a commonly used strategy by SMEs to identify and address Cloud
security risks (Carcary, Doherty, Conway, & McLaughlin, 2014; Kumar, Samalia, & Verma,
2017).
Research Methodology and Design
The decision to approach this research topic on a qualitative case study basis with a
Delphi instrument was based on several factors (Chan, & Mullick, 2016; Flostrand, 2017; Ogden,
Culp, Villamaria, & Ball, 2016). The primary factor is that the product of this research study is a
new approach to SME Cloud computing risk assessments and a validated risk assessment tool
that SMEs can use going forward. With this research study the researcher is not building on
theories from previous studies but looking to discover a thesis and answers from analyzing what
SMEs are currently doing. The most appropriate way to generate new theses and answers from
research based on what organizations are currently practicing is through the use of case studies
(Leung, Hastings, Keefe, Brownstein-Evans, Chan, & Mullick, 2016; Waterman, Noble, & Allan,
2015). There are currently no easily adaptable tools for SMEs to use as they decide to adopt
Cloud computing (Huang, Hou, He, Dai, & Ding, 2017; Kritikos, Kirkham, Kryza, & Massonet,
2015; Lacity & Reynolds, 2013). This case study-based research study used an appropriate
Delphi technique to harness the expertise of a large group of subject matter experts and to
synthesize the output of that expertise into a useable product (Flostrand, 2017;
60
Ogden, Culp, Villamaria, & Ball, 2016). Using case study-based recordation and analyzation
techniques on the replies of the subject matter experts that belong to a local ISACA chapter was a
unique chance to create new theory and validated risk instruments.
In other academic fields, a researcher may do well with a grounded theory-based
methodology. A grounded theory design would be an appropriate choice in similar circumstances
except for several major flaws. If there are SMEs risk teams that have created a validated risk
instrument or have answered the research questions in this study, they have not shared them
(Chiregi & Navimipour, 2017; Lacity & Reynolds, 2013; Liu, Xia, Wang, T., Zhong, 2017). If a
researcher built a study on grounded theory coding techniques of SMEs that are in the process of
solving the research questions, the SMEs would not share the additional and ancillary
information critical to grounded theory coding processes due to security concerns (Korte, 2017;
Ring, 2015). The same reticence on the part of cybersecurity professionals rules out quantitative
approaches in general. Quantitative based research study methodologies such as experimental,
quasi-experimental, descriptive, or correlational are not appropriate for two main reasons. The
subject population that can provide answers posed by the survey instruments of this research
study are a very select group and a very small portion of the general population. Random
selection is not possible given the specific knowledge required of the participants of this research
study. A second major concern that obviates the ability to use quantitative methods is that
cybersecurity professionals are not able to share specific details of their work or their
organizations’ challenges (Lalev, 2017; Ring, 2015). Ethnographic, narrative, and
phenomenological methodologies did not fit the focus of this research study. Perhaps the most
important reason for a qualitative case study approach for this research study is that the answers
61
are not evident and reporting and proving the answers is a useful addition to the field of
academic research and standard industry practices.
This research study was based on the replies from a group of risk subject matter experts
to a multi-round web-based survey. The publishing of a web link to the first round of the survey
on the home page of the greater Washington D.C. chapter of ISACA is the way the subject matter
experts accessed the survey instrument. All respondents received a random identification number
based on the order in which they responded to the survey.
The first round of the web-based survey contained general demographic questions such as
the respondent’s risk background, professional role, and size of organization that employs the
respondent. Careful consideration is important on the demographic based questions for both
ethical grounds and security grounds. Cybersecurity professionals have rarely gained permission
to share any information that may identify weaknesses within their organization (Wilson &
Wilson, 2011). The second section of the first web-based survey included general questions about
risk assessments, Cloud security, and SMEs. Sample web-based survey questions included those
similar to the following. How long have you worked in an IT risk-based field? Have you created
or used risk-based tools to assed your organization adopting Cloud computing? What are some of
the deficiencies you have witnessed in using risk assessments created for on-premises computing
environments? Analysis of the differences and similarities of these responses should be the major
driver in creating the questions based on the second-round web-based survey (Mustonen-Ollila,
Lehto, & Huhtinen, 2018). As researcher used the Delphi technique in this research study, the
second web-based survey asked the participants to assess the results of the first web-based survey
and create new subjects or concepts (Greyson, 2018). Continued analysis of the answer took
62
place with the second-round results and led to the creation of the third round of questions
(Mustonen-Ollila, Lehto, & Huhtinen, 2018).
Population and Sample
The population for this research study was the approximately three thousand strong
current membership of the greater Washington D.C. chapter of ISACA. ISACA is a nonprofit
global association that authors COBIT, a framework for IT governance, and certifications for
audit, governance, and risk professionals (da Silva & Manotti, 2016). A paid membership in
ISACA is a strong indicator that the subject is interested enough in a risk assessment related field
to spend approximately $200 a year to be a member. Membership in an ISACA chapter by itself
is an indicator that the member is not only a risk professional but an expert in the field (Lew,
2015). The sample used in this research study was self-selecting based on members of the D.C.
area chapter of ISACA that respond to the advertisement of this research study. The board of
directors for the local chapter gave permission to place a short article advertising this research
study on the main page of the chapter’s website and granted informal site permission.
The estimated number of members that could have responded to the study ranged from
approximately one hundred replies based on the local chapter’s board of directors estimates to
approximately twenty members based on research on web-based survey tools (Bickart &
Schmittlein, 1999; Brüggen & Dholakia, 2010). There are indications from previous Delphi
studies that much lower numbers such as ten to twenty respondents can be effective in reaching
saturation (Gill, Leslie, Grech, & Latour, 2013; Ogden, Culp, Villamaria, & Ball, 2016). A
response rate of less than one per cent of the local ISACA chapter satisfied a twenty to thirty
subject count. If the response rate was less than one per cent, there is a potential to include other
ISACA chapters or LinkedIn groups in the population to increase respondent counts.
63
Materials and Instrumentation
The main instrument for this research study was an online or web-based survey
instrument with three rounds. The responses to each round played a major role in the creation of
the next round of questions through the review and analysis of the responses process
(MustonenOllila, Lehto, & Huhtinen, 2018). The first round of questions included general
demographic questions and open-ended multiple-choice questions that directly tie back to the
research study questions. The structure of the survey was such that respondents answer questions
from the general IT risk domain and then progress to the specific Cloud risk field. While the
survey questions were new, the questions only used standard terms and paradigms in the IT risk
framework. As part of the case study-based review and analysis process, the first round of
questions was the basis for the researcher to inductively generate the next round of questions and
the discovery of a theory that describes how SMEs can secure Cloud computing environments.
Appendix A includes sample survey questions in a spreadsheet.
The researcher created the survey using the software SurveyMonkey (SurveyMonkey,
2018). SurveyMonkey is a comprehensive solution with sample validated questions and
instructions for creating effective survey questions, however, the questions for this research study
were new to this research study. This research study included the definition of standard industry
terms as part of the survey questions. No questions used non-standard industry terms. ISACA’s
COBIT 5, a framework for the governance and management of enterprise IT provided any
definitions of standard terms needed (da Silva Antonio & Manotti, 2016). It is reasonable to
expect risk subject matter experts to either be familiar with COBIT 5 terms or be able to
reference them as needed.
64
The researcher used standard and recommended design elements such as the use of a five-
point Likert scale, free form text boxes and checkboxes. The collection of this type of
quantitative data allowed the researcher to discover where there is a consensus of ideas and
provide an opportunity to hone in on a unifying theory and validated risk instrument (O'Malley &
Capper, 2015). Future researchers will be able to change the text of any question while remaining
in standard design formats such as Likert scales. The survey questions did not follow a particular
framework such as Technology Organization Environment theory (TOE) but instead the focus of
the questions was on fact finding and straightforward response generation.
The result of this research study includes a validated risk instrument that is freely
available and usable by the general SME community. The participants of the web-based survey
and other members of the local ISACA chapter may help validate the risk instrument at some
future point. Publication of the finished risk instrument product will take place on the web page
of the local ISACA chapter and comments requested. As the risk instrument should be usable by
SME staff that may not be expert risk professionals, there may be a need for validation of the
finished risk instrument by outside review groups as the local ISACA chapter members may have
a bias towards validating the Cloud risk instrument because they contributed to its creation. The
use of the appropriate SME LinkedIn groups should provide the necessary sample on nonrisk
experts if needed.
Study Procedures
A short article including a link to a web survey hosted on the SurveyMonkey site
appeared on the front page of the Greater Washington D.C. ISACA chapter. Review and analysis
of all responses to the survey that answer the majority of the questions took place. Once
analyzed, incorporation of the first-round responses into the study took place and the potential
65
respondents received a second link based on the SurveyMonkey website. A similar review and
analysis procedure took place for all responses to the second-round survey that answer the
majority of the questions. Once analyzed, incorporation of the second-round responses into the
study followed and the potential respondents received a third link based on the SurveyMonkey
website.
Once the researcher performed a case study-based review and analysis of the survey
results, the researcher identified a consensus on what is working, and creation of a risk
instrument that is usable by SMEs was the next step. The risk instrument consists of a web-based
SurveyMonkey survey. The finished risk instrument has the same simple branching question
format as the one used by this research study. The risk instrument has distinct sections of
demographic, IT related, and CSP related questions. The risk instrument IT and CSP questions
are adaptive based on the demographic responses. If the risk instrument user indicates that their
organization is a particular size in a particular industry, the following questions for the
organization’s IT staff changes. The same is true for following questions for a potential CSP. For
example, if the risk instrument user indicates that they are a small enterprise in the health care
industry, the risk instrument branch to a set of questions for potential CSPs that ask pertinent
questions for such an organization.
Review of the finished risk instrument by the risk experts in the local ISACA chapter and
non-risk expert SME employees as discussed previously may take place based on voluntary
participation. A successful validated risk instrument must be usable by non-risk experts. The
projected audience of the risk instrument includes SME IT teams and SME accounting
departments. Many SMEs have no dedicated cybersecurity personnel and rely on general IT staff
for all related IT and cybersecurity functions (Wang & He, 2014). SMEs commonly do not have
66
dedicated risk or audit teams and rely on members of the accounting team to evaluate financial
costs and risks for new expenditures such as adopting Cloud computing (Assante, Castro,
Hamburg, & Martin, 2016; Gritzalis, Iseppi, Mylonas, & Stavrou, 2018; Hasheela, Smolander, &
Mufeti, 2016). Evaluation of the final risk instrument by a representative group of SME IT and
accounting staff is a primary step for validation. The intent of the validated risk instrument is to
allow non-Cloud expert SME staff to ask and answer the appropriate questions for their
organization. The risk instrument will also help SMEs decide the appropriate control sets to use
for their organization. While approval and use of the risk instrument by subject matter experts
and general business users is no substitute for academic testing and validation, acceptance by the
IT risk assessment community will be a useful data point for future academic research.
Data Collection and Analysis
The researcher used commonly accepted case study techniques and processes to analyze
the data gathered from the subjects of the local ISACA chapter. Although the collection of the
information takes place via web-based surveys, the subjects were able to respond to many of the
questions in a free form text manner that emulates responding to interview questions. This
allowed the subjects to respond in as much detail as they wish and were allowed to by their
organizations (Mustonen-Ollila, Lehto, & Huhtinen, 2018). Although there were few respondent
comments, the use of a memoing technique after return of the responses took place along with
electronic recordation and formatting for long term storage of all subject answers. Common field
interview drawbacks such as logistics were not be a factor in this research study. Creswell’s data
analysis spiral is a visual representation of how this research study processed and analyzed the
data collected from the web-based surveys (Creswell, 2007).
67
Figure 1. Creswell data analysis spiral. This figure visualizes the data analysis process.
(Creswell, 2007).
After collection of the first round of survey responses, the researcher created preliminary
categories (Ogden, Culp, Villamaria, & Ball, 2016). The researcher repeated this process after
each succeeding round, including deciding which category shows the most consensus among
respondents either for what works or what has failed in the Cloud security risk assessment
process (Parekh, DeLatte, Herman, Oliva, Phatak, Scheponik, Sherman, 2018). Based on the
appropriateness or usefulness of the central category, alteration of the succeeding round of
questions took place to produce a new central theme. For example; if a particular security
concern or the use of a specific technique emerges from the first round of questions, then the
second round of questions would have focused on that security concern. The new and focused
categories would have included which part of the risk field the respondent is most experienced in
and other demographic categories (Ogden, Culp, Villamaria, & Ball, 2016). The categories also
include on which type of risk assessments or analyses the subject has based their response. For
example, respondents that have vast experience in compliance-based audits will focus on
different aspects of Cloud computing environment risks than a respondent that commonly uses a
tool such as the Center for Internet Security (CIS) benchmarks as the basis for their assessments
68
(Center for Internet Security, 2018). After completing review and analysis of the second round of
responses, the researcher conducted a final phase of review and analysis (Ogden, Culp,
Villamaria, & Ball, 2016). As one of the end goals of this research was to develop a validated
risk instrument for SMEs, the entire process was focused on the end goal of presenting a useful
tool for SMEs.
Once the review and analysis process ended, the next step was to create a simple risk
instrument from the results. The risk instrument starts with demographic questions to branch into
the questions for the organization’s IT staff and potential CSPs. The business decision makers
and risk assessors of SMEs now have a simple tool to ask the correct questions of their IT staff
and potential CSPs based on the results of this research study. The first part of the research study
generated a new thesis and the second part packages that thesis and knowledge into a useful tool
for SMEs. The validated risk instrument allows SMEs to properly evaluate Cloud computing
adoption risk by showing the SMEs which questions they need to have answered. As discussed
previously, the risk instrument will help the SMEs identify what they need to know from their IT
teams and potential CSPs.
Assumptions
Research methodological assumptions are particularly important in qualitative case study-
based research and perhaps more so for case study research using a Delphi panel (Parekh,
DeLatte, Herman, Oliva, Phatak, Scheponik, Sherman, 2018; Wiesche, Jurisch, Yetton, &
Krcmar, 2017). The researcher is developing new theses from case study data collection and
assumptions play a large part in the results of the research study. During the review and analysis
of data in this research study, one may embrace different realities or ontological viewpoints
(Parekh, DeLatte, Herman, Oliva, Phatak, Scheponik, Sherman, 2018). One goal of the
69
researcher for this research study was to find a solution and create a validated risk instrument, so
the researcher took care to make sure that the data supports any reality or paradigm discovery
from the data review and analysis process. It was tempting for the researcher to base acceptance
of a paradigm with a solution rather than a paradigm the truly fits the results of the data coding.
The researcher was open to the possibility that there is no current solution to assessing Cloud
security risks for SMEs. The research properly done, led to the methodological assumptions
being paramount. The design of the review and analysis process of this qualitative case
studybased research study was to start with discrete facts and to weave them into an overarching
theory that explains the connections between the details (Glasser, 2016). Each succeeding round
of the Delphi technique elucidated additional results that inductively got closer to a true solution
and a workable validated risk assessment instrument.
Epistemological assumptions of this research paper focus on alternative ways in which to
gain subjective knowledge from the participants of the web-based survey (Guba & Lincoln,
2008). The cybersecurity field is a very difficult one in which to practice field research and to get
close to subjects (Lalev, 2017; Ring, 2015). This research study attempted to ameliorate the
negative results of a lack of subjective closeness between the researcher and the subjects through
the use of a Delphi technique (Johnson, 2009). On the positive side, being that all contact
between the researcher and the subject population was through responses to a web-based survey,
the researcher assumed that it took less effort to increase the distance between the researcher and
the subjects. (Parekh, DeLatte, Herman, Oliva, Phatak, Scheponik, Sherman, 2018).
Axiological research assumptions include the biases, predilections, and beliefs of the
researcher (Denzin, 2001). Axiological research assumptions for this research study include the
researcher’s industry and practical experience as a multi-decade long member of a cybersecurity
70
team. When discussing whether a Cloud computing environment is secure, the default and
immediate reaction of a cybersecurity team member is “No” (Aljawarneh, Alawneh, & Jaradat,
2016; Kholidy, Erradi, Abdelwahed, & Baiardi, 2016; Lai, & Leu, 2015). As the researcher has
the assumptions and biases of a cybersecurity team member, data coding was more rigorous and
exhaustive than it might be if the researcher had a different background. The researcher
anticipates that there is a need to take care to avoid rejecting paradigms that successfully explain
the coded data because they provide a way to make Cloud computing secure.
Limitations
General limitations include funding, time, and access to the subject population. This
research study does not require funding as the expected costs include only a temporary paid
SurveyMonkey account. Limitations to this study did not include time pressures. Although the
limited time period for completing the research phase of this study, the design of this research
study led to completion in a timely manner primarily through the use of easily and quickly
accessed web-based surveys. Access to the subject population was the greatest possible limitation
to this research study. The researcher has spent several years volunteering, teaching, and working
with the board of the local ISACA chapter. The researcher has already obtained site permission to
reach the members of the local ISACA chapter and is continuing to build bonds with the local
ISACA chapter governing bodies.
Cybersecurity professionals do not have permission to share detailed information
regarding what their organizations do to combat threats (Beauchamp, 2015; Lalev, 2017; Ring,
2015). This study attempts to mitigate this limitation by using a Delphi technique with webbased
survey questions that do not require disclosure of specific identifiable information. Another
potential limitation is the risk of subject drop-outs on later rounds of the Delphi technique
71
(Ogden, Culp, Villamaria, & Ball, 2016). Starting with a large number of participants should
ameliorate this risk. If the number of first round respondents is too low, additional steps such as
using LinkedIn groups to increase the number of subjects may take place. The design of this
research study as a qualitative case study-based research study is a potential limitation and
perhaps also a delimitation. Instead of statistically verifiable experimental results, this research
study depends on the inductive reasoning process of the researcher as he reviews and analyzes
the responses (Guba & Lincoln, 2008). While the researcher is an experienced industry
practitioner, the researcher is not yet an experienced expert academic researcher. With the help of
this research study’s dissertation committee, the researcher expects to reach the required level of
academic expertise.
Delimitations
A major delimitation of this research study was the choice of participants (Gomes et al.,
2018). The population for this research study was only those subscribing members of a local
ISACA chapter. This selection criteria was central to the design of this research study and the
research questions. A qualitative case study-based theory research project using a Delphi
technique needs experts (Strasser, 2017). The use of experts implies a limited population.
Additional rounds of a Delphi technique supply additional data needed to complete the review
and analysis process (Strasser, 2017). The design of the problem statement and purpose statement
presumes answers by experts. The problem stated in this research study is a narrow and specific
one that a random sample of any particular population cannot answer. The researcher has
designed answerable research questions for a group of experts with the aforementioned constraint
that they not share specific data on their organization’s cybersecurity activities including risk
assessments of Cloud computing environments.
72
The research decision to investigate solutions to SME risk assessments of Cloud
computing environments had direct ties to the availability of a large subject matter expert sample
of risk professionals that are members of a local ISACA chapter. The researcher has spent several
years working with these experts and the opportunity to collect data from such an expert group
was too great to pass up on. Once the researcher made the decision to use the risk subject matter
experts belonging to the local ISACA chapter, a Delphi technique seems obvious. The use of a
Delphi technique to answer the research questions lead to the selection of a qualitative case
study-based theory approach. Multiple levels of coding enhanced the power of a large group of
experts focused on the research questions of this study (Trevelyan & Robinson, 2015).
Ethical Assurances
The researcher received approval from Northcentral University’s Institutional Review
Board (IRB) prior to data collection. The risk to participants was minimal. No collection of
personally identifiable information (PII) took place. The researcher assumed that access to and
participation on the local ISACA chapter website is proof of expertise. The limited demographic
data collected is not able to identify participants. The intent was to design the web-based survey
questions as generic enough that a bad actor cannot identify respondents’ organizations. For
example, questions relating to the industry or size of a respondent’s organization offers responses
in broad categories and not specific numbers. Only sharing of the data from the responses in
aggregate numbers will take place.
The storage of data from the study including all rounds of the Delphi technique using a
web-based survey instrument follow the Northcentral University’s requirements. Compression
and encryption of the data will take place. The researcher will then upload the data to a free
Gmail account. Storage of the encryption key will be in a LastPass password manager account.
73
Magnification of the researcher’s role in this research study can happen by the qualitative
multiple case study-based theory framework. The researcher reviewed and analyzed data from
multiple sources during three phases and personal and professional biases could have easily
influenced the theory discovery process based on the researcher’s view of the data. Personal
biases are a lesser concern for this research study as collection of the data uses a web-based
survey instrument. There was no personal interaction with the subject population. The research
study did not collect demographic data regarding race, sex, nationality, or any other factor that
could play into personal bias by the researcher.
Professional experience bias is a greater concern. As the researcher has spent decades on
cybersecurity teams, the concept that one can never fully secure data stored on someone else’s
computer is a truism. The long professional career of the researcher has also deeply ingrained the
idea of rapid change in IT. The researcher understands that Cloud computing adoption is rampant
and increasing at a rapid rate (Bayramusta & Nasir, (2016). The tone of this research study is
deeply optimistic. The goal is to find a solution to SMEs’ adoption of Cloud computing securely.
While the researcher’s professional experience is likely to cause greater scrutiny on data coding
results that appear to offer solutions, that is a feature of good research
Summary
Professionals in SMEs need proven ways to evaluate risk in adopting loud computing
environments and this qualitative case study-based theory research study has produced a
validated risk instrument for that purpose. The research methodology and design of this study
included web-based survey instruments, and a Delphi technique. Review and analysis of the data
collected from the three rounds of web-based surveys used case study-based theory techniques
and the results formed the basis of a freely available Cloud computing risk assessment instrument
74
for SMEs. The rarely available subject population is the key to this research study and the basis
for all design and methodology decisions. The design of this research study intends to yield
maximum results from a large group of IT risk subject matter experts based on membership in a
local chapter of ISACA.
75
Chapter 4: Findings
The researcher’s purpose with this qualitative case study was to discover an underlying
framework for research in SME risk analysis for cloud computing and to create a validated
instrument that SMEs can use to start assessing their risk in cloud adoption. To determine if they
are ready to transition to cloud computing, SMEs need a process or validated instrument such as
a risk assessment (Bildosola, Rio-Belver, Cilleruelo, & Garechana, 2015; Carcary, Doherty, &
Conway, 2014; Hasheela, Smolander, & Mufeti, 2016). Current research does not show that
SMEs using a risk-based approach have reached a consensus on how to identify and address
cloud security risks. (Carcary, Doherty, Conway, & McLaughlin, 2014; Kumar, Samalia, &
Verma, 2017). In this chapter, the researcher describes the ways in which this research study
achieved trustworthiness of the data. Also, in this chapter, the researcher presents the results of
the research including how the researcher answered each of the four research questions.
Trustworthiness of the Data
The researcher confirmed the trustworthiness of the qualitative data gathered in this
research project by prolonged engagement, triangulation, transferability, dependability, and
confirmability. Prolonged engagement for this research study involved the researcher being a
member of the local chapter of ISACA (GWDC) for over five years and volunteering for over
one hundred hours of conference events hosted by the local chapter. The researcher worked hard
to build a close and effective volunteer relationship with the local chapter officers. This research
study was the first one supported by GWDC and the first that GWDC allowed to use the local
chapter email list and chapter events to promulgate the three web surveys. Prolonged engagement
with GWDC by the researcher led to the researcher gaining the trust of the subject population of
risk experts. Familiarity with the field of risk assessment and the expert practitioners of risk
76
assessments by the researcher helped to make sure the survey questions were based on pertinent
risk assessment practices. The research project was a three round Delphi panel with anonymous
participation. The survey questions were specific to the risk assessment field and required expert
knowledge of the field to answer coherently.
As the research was based on anonymous surveys, the primary type of triangulation was
that of data triangulation. The same group of respondents may have completed each survey or a
totally different group each time. The researcher designed each of the surveys to ask questions
related to each of the four research questions. The design of several questions in each of the three
surveys intended to elicit consistent responses to those asked in the other two surveys. For
example; survey one, question eleven that asks “What IT security control standards do you see
SMEs using?” and survey three, question thirteen asking “Once controls have been identified for
the SME’s Cloud environment, what effect do they have on existing SME IT controls?” were
purposely asked in separate surveys rather than one right after the other as a way to increase data
triangulation.
The use of three web surveys is a simple form of method triangulation. A GWDC
newsletter announced each survey, and the researcher used the SurveyMonkey web-based tool
for each survey so the method triangulation was weak but each survey presented questions
differently than the other surveys. For example; survey one used two questions for each major
point, such as question ten “For SMEs that are planning to adopt Cloud computing, do you see
SMEs using IT security control standards?” and question eleven “What IT security control
standards do you see SMEs using” would be one question in survey two or three. Survey two had
questions that directly referenced the results of survey one such as question ten “100% of
respondents to survey 1 have seen recommendations to outsource the transition to a Cloud
77
environment. Which portions of a transition to a Cloud environment have you seen
recommended to be outsourced?” There was only one researcher so investigator triangulation
was not possible. During the coding portion of the data analysis the researcher used a simple
form of theory triangulation when grouping results of the survey questions under each research
question.
There are limits to the transferability of the data due to the very specific field that the
questions focused on. Within the field of Cloud computing risk assessments, however, the
transferability of the data is very strong due to the consistent format of the surveys as web based
with questions predominately presented as multiple choice. The researcher does not need to
provide thick description where the researcher “provides a robust and detailed account of their
experiences during data collection” (Statistics Solutions, 2019) for this research project as the
data is three series of questions with multiple choice answers. The use of a Delphi technique
specifically reduces the subject population to subject matter experts in a particular topic (Choi &
Lee, 2015; El-Gazzar, Hustad, & Olsen, 2016; Johnson, 2009). By reducing the participants to
risk subject matter experts, the researcher greatly lessened most of the concerns about
transferability due to broader social or cultural concerns regarding data collection or participants’
biases. Further reducing the subject population to those experts that are members of a local
geographical based chapter of an international risk professional association helps to reduce
potential cultural biases when answering the survey questions. Risk assessments are fact finding
exercises and risk assessment results are statements of success and failure (He, Devine, &
Zhuang, 2018). Risk assessments and audits avoid emotional or culturally based descriptors or
modifiers. (King et al, 2018).
78
The researcher can state many of the results of this research project in simple declarative
statements such as “100% of risk experts surveyed found that SMEs have gotten
recommendations to transit to Cloud computing operations”. While the interpretation of how
various questions within each of the three surveys relate to each other may change when viewed
by other researchers, the basic information gained by surveying D.C. area risk subject matter
experts on specific Cloud computing risk assessment topics is clear and transferable with high
fidelity to the original results. One can never completely eliminate bias on the part of the
researcher or participants but the use of multiple-choice questions based solely on a fact-based
profession that requires declarative statements as the work product goes a long way to reducing
any potential bias (de Bruin, McCambridge, & Prins, 2015).
The researcher’s design of this research study is that of a qualitative case study approach
with a Delphi technique. A qualitative approach using a case study methodology is the best
solution for dependability when trying to elucidate data from cybersecurity professionals
regarding potentially confidential processes. A problem solved by using a qualitative case study
approach is that the subject population of risk-based Cloud computing research experts were able
to respond with qualitative data but not quantitative numbers to avoid compromising their
organization’s security (Glaser, 2014). Using a three-round survey with multiple choice questions
allows cybersecurity professionals to answer questions regarding Cloud transition risk. This
improves the dependability as future researchers can ask the same questions without concern that
respondents will not be able to answer.
The researcher’s use of a Delphi technique, in the case of this research study, improves
the dependability of the data gathered in this research study. Limiting the subject population to
experts in the risk field reduces the variability of potential subjects for both good and bad (Lu,
79
2018). In the case of dependability, reduced variability makes the research study easier to
replicate if one uses the same strictures on respondents. The use of a Delphi technique allowed
the researcher to pose specific questions about a very narrow field. The more specific the
questions, the more easily a future researcher can replicate the study. The use of multiple-choice
answers also increases the ease in which a future researcher may be able to replicate this study. If
the future researcher wants to add new choices based on recent technology or a different research
focus, they will be able to just add more choices to existing questions. While there is always the
chance that questions reworded to add or remove bias may gather different answers in a future
research study, short simple answer choices remove some of that problem (Bard & Weinstein,
2017).
The dependability of the data from this research study is very strong aside from one
hurdle. If a future researcher gains access to GWDC, then the researcher could simply replicate
the study completely by posting the same three surveys. Based on the local chapter’s board with
this research project, they have verbally agreed to similar efforts in the future. The international
chapter of ISACA is pushing to have greater student involvement and research projects such as
this would help further that goal. Future researchers attempting to replicate this research study
would most likely find approval from the local chapter board if the researcher was a member of
the chapter and a student. If a future researcher wished to replicate this study without being a
member of the local chapter, they would need to increase efforts to reach risk experts. The future
researcher would also have to devise a way to make sure that the respondents were actual risk
experts. One of the benefits of limiting the population to members of the local ISACA chapter is
that it is reasonable to conclude that only risk professionals would agree that paying international
80
and local dues in the current amount of one hundred and sixty-five dollars a year to ISACA is
worth doing.
The researcher used a straightforward approach to address the confirmability of the data
(Korstjens & Moser, 2018). This research study is based on a Delphi technique and surveys risk
experts using multiple choice questions. The data received from the surveys is clear and easily
summarized by each question in simple to read tables. Presentation of pertinent tables takes place
when discussing the research questions. Suspected bias in answering multiple choice questions
can be determined by looking at the survey results broken down by respondents. After looking at
results grouped by respondents, the researcher discovered no such bias and readers can find the
results by respondent in the Appendix. Readers may check for bias by the researcher in this
project by reading the multiple-choice questions and potential answers. The field of research is
very narrow and focused on risk assessments related to a SME transitioning to a Cloud
computing environment. The use of loaded terms with emotional overtones is not apparent in the
questions or the answer choices. The researcher took care to change the question style between
surveys to eliminate unconscious attempts to lead respondents to a particular answer. For
example; survey one generally asked two questions for each area of focus. Survey one, question
eighteen “Do you see SMEs adopting Cloud security controls?” and question nineteen “What
Cloud security controls do you see SMEs adopting?” are an example of this. Some of survey two
questions had multiple sentences in the question and did state assumptions in the question but the
assumptions did not include emotional or bias elements. For example; Survey two, question 7
“Most SMEs have Cloud operations in progress. Which scenarios have you seen and which have
you seen audited by SMEs?” states the assumption that most SMEs have current Cloud
operations.
81
Results
With this research study, the researcher used a Delphi technique with three rounds of
surveys to ask risk assessment experts questions about cloud computing adoption by SMEs and
the risk assessment process involved with the SME’s transition to the cloud. The presentation of
survey instrument questions follows the four research questions in the study. The researcher
gathered data for each of the four research questions and presents and organizes the results are by
research question in this chapter. The survey instrument questions had multiple choice answers.
Design of the questions differ in some ways to elicit accurate and consistent answers.
RQ1. What are the current frameworks being leveraged in Cloud specific risk
assessments? When answering survey questions related to this RQ, respondents described several
frameworks showing common use. RQ2. What are the primary categories of concern presently
being addressed in Cloud specific risk assessments? Respondents answered this RQ with
multiple concerns with one concern very prevalent. RQ3. What are the commonly used and
tailored security controls in Cloud specific risk assessments? Answering this RQ happened at a
high level with several control families predominant. RQ4. What are the commonly
recommended mitigations in Cloud specific risk assessments? Respondents also answered this
RQ with several mitigations currently in use. This chapter organizes survey instrument questions
and answers by research question.
The participants were anonymous. There was no requirement for participants to give their
names. The research process involved three web surveys hosted by SurveyMonkey. The survey
instrument did not track or record of the IP addresses of the respondents. GWDC shared the
surveys’ web links via the Washington D.C. chapter of ISACA (GWDC) weekly newsletter, the
82
GWDC website and at GWDC one day conferences. This had a purposeful effect of limiting the
population to members of ISACA in general and GWDC specifically. Participants did not have to
have a membership in GWDC but the limited dissemination of the web links worked to limit the
population to GWDC members for the most part.
Aside from probable membership in GWDC which assumes the subject population is
based in the D.C. geographic area, the demographic details of the respondents are not known in
great detail. To take part in each of the surveys the respondents had to say that they were eighteen
years or older and that they had at least five years of risk experience. The researcher decided not
to collect further demographic details of the respondents. The researcher determined that it was
sufficient for the respondents to give their expert opinion on Cloud computing risk. Age other
than adult, gender, or nationality do not impact the respondents’ replies to the multiple-choice
questions in the surveys.
The designs of the surveys included strong efforts to let respondents be as anonymous as
possible and to not require demographic detail due to the sensitive nature of the survey questions.
The survey questions are not personally sensitive to the respondents but the questions would be
sensitive if the question involved a specific SME. The professional cybersecurity population
rarely has permission to discuss their SME’s cybersecurity efforts in any detail due to SME
concerns about giving adversaries damaging information. Cybersecurity risk professionals face
the same constraints. The design of the surveys focused on making sure that there was no
possible identification of respondents or the SME that employs them from any possible
combination of the data gathered in this research study.
As the survey questions are predominately multiple choice, the coding process for this
research study is seemingly straightforward. Complex and complicated coding was not an
83
effective option when the survey respondents were truly anonymous but some themes still
emerged. The age, ethnicity, gender, or life experiences of the respondents to the three surveys in
this research study cannot be determined. Survey questions were very focused on a narrow field
of expertise and this research study does not require demographic details of the respondents. On
the other hand, as this research study uses a Delphi technique to survey a group of experts, even
small differences in results can lead to new themes discoveries.
Because the recruitment of respondents took place through a Washington D.C. chapter of
a professional risk association, government experience is likely for many of the respondents. One
can find confirmation of this government experience in some of the responses to certain survey
questions. For example; survey one, question eleven asked about IT security controls. The
responses look at least partially tilted to NIST security control standards that the U.S. federal
government uses. Response to survey one, question thirteen offers further confirmation of the
federal background of some of the respondents. The top three choices by respondents to survey
one, question thirteen are Federal government based. DoD, DISA, and FedRAMP Cloud security
baselines. The Federal government IT frameworks and Cloud security controls are based on a
compliance paradigm. To remove this potential Federal government bias, surveys two and three
questions avoided potential compliance-based questions for the most part.
An additional research question one related theme, is that current frameworks in use are
not as current as they might be. More respondents reported seeing existing frameworks and
guidelines in use that either are not Cloud focused or have creation dates well before Cloud
computing was predominant. Although respondents see SMEs accepting CSP attestations and
SLAs, they are not using the CSPs advanced security tools. Even SMEs, more nimble and more
easily able to change than large enterprises, do not keep up with the dramatic changes in Cloud
84
computing. This strongly relates to the predominant theme discovered by replies related to
research questions two and three.
The biggest theme, and the one that most of the coding process led to, is that SMEs do
not have Cloud capable staff. SMEs respond to research question two with a resounding
uniformity. Lack of properly trained IT staff is the major theme of research question two results.
SMEs’ lack of Cloud trained staff affects every research question in this study. By far, the
consensus of the risk experts surveyed is that SMEs need outside help with Cloud transitions.
When SMEs have the choice of either investing in their IT staff, or outsource or contract out
work involved in the SMEs Cloud transition, risk experts recommend outsourcing. In relation to
research question three, the risk experts recommend controls that rely on third parties.
Commonly recommended mitigations, research question four, also relied heavily on third-parties
or outsourcing.
Research question 1. What are the current frameworks being leveraged in Cloud
specific risk assessments?
Tables present pertinent survey questions and the respondents’ answers below for clarity.
The researcher designed several survey questions related to research question one to be
exploratory and level setting to make sure the subject population was the appropriate group to
answer the other survey questions. The purpose of some survey questions was to cross-check
previous survey questions. All survey question tables are in appendix B.
Survey one, question nine asked which IT related frameworks are SMEs adopting. This
question directly addresses research question one. Respondents reported three common IT
frameworks as commonly used by SMEs with COBIT, ITIL, and ISO/IEC 38500 each receiving
eleven of nineteen replies. The responses to this question helped direct the focus of surveys two
85
and three. The answers to this survey question help to identify a common theme of SMEs not
using current or best practice frameworks.
Table 1
Survey 1. Q9: What IT related frameworks (partially or completely) do you see SMEs adopting
Answer Choices Responses Count
COBIT (Control Objectives for Information and Related
Technologies)
61.11% 11
ITIL (formerly Information Technology Infrastructure Library) 61.11% 11
TOGAF (The Open Group Architecture Framework for enterprise
architecture)
27.78% 5
ISO/IEC 38500 (International Organization for
Standardization/International Electrotechnical Commission Standard
for Corporate Governance of Information Technology)
61.11% 11
COSO (Committee of Sponsoring Organizations of the Treadway
Commission)
38.89% 7
Other 16.67% 3
A large proportion of respondents to survey one have seen Cloud security configuration
baselines used by SMEs. Survey one respondents identified many Cloud security configuration
baselines in use by SMEs with no one baseline predominant. Respondents choose the federal
government-based Cloud security configuration baselines at a higher rate than normal for a more
general risk expert population. As the subjects were members of a D.C. based risk organization, a
86
bias towards government-based examples the researcher should have expected this result.
Identification of this minor theme occurred early in the coding process, and the design of surveys
two and three mitigated its effects.
Table 2
Survey 1, Q 13: What Cloud security configuration baselines have you seen used by SMEs?
Please select all that apply.
Answer Choices Responses Count
DoD Cloud Security requirements guides (Department of Defense) 62.5% 10
DISA/IASE Security requirements guide (Defense Information
Systems Agency Information Assurance Support Environment)
56.25% 9
CSA Cloud security guidance (Cloud Security Alliance) 31.25% 5
FedRAMP Cloud security baselines (Federal Risk and Authorization
Management Program)
68.75% 11
AWS SbD (Amazon Web Services Security by Design) 50% 8
CIS Cloud baselines (Center for Internet Security) 50% 8
Other 0% 0
A majority of survey two respondents do not see the use of current frameworks changed
as a result of Cloud transitions. This directly applies to research question one and is related to a
theme discovered in this research study. If Cloud specific risk assessments are not changing the
framework used by a SME, perhaps a Cloud environment does not need a new or tailored
framework. Most likely the theme of SMEs not using the best frameworks for a Cloud transition,
87
however, is directly related to the major theme of this research study; that SMEs do not have
properly trained Cloud personnel.
88
Table 3
Survey 3, Q14: Have you seen Cloud risk assessments change other previously completed SME
risk assessments in the ways listed below? Please select all that apply.
Answer Choices Responses Count
Previous risk assessments changed because of CSP location. 6.25% 1
Previous risk assessments changed because of new legal or
regulatory requirements based on Cloud usage.
37.50% 6
Previous risk assessments changed because of new financial
requirements based on Cloud usage.
6.25% 1
Previous risk assessments changed because of new insurance
requirements based on Cloud usage.
6.25% 1
Previous risk assessments changed because of new market
requirements based on Cloud usage.
0% 0
Previous risk assessments changed because of new operational
requirements based on Cloud usage.
37.5% 6
Previous risk assessments changed because of new strategic
requirements based on Cloud usage.
6.25% 1
Other (Please describe) or any additional comments (We want your
expertise)?
0% 0
As a refutation to the conclusion that Cloud specific risk assessments are not changing the
framework used by a SME the results of survey three, question fifteen show that Cloud
transitions are changing SME risk and audit teams. Most respondents to survey three see an
89
increased work load and rate of change for SME risk assessment teams. This is slightly tangential
to research question one, but does indicate that there is an increased use of frameworks. In the
coding process, the results of this survey question indicate that there may be a valid counterpoint
to assuming that current frameworks are not changing.
Table 4
Survey 3, Q15: Cloud transitions almost always promise cost saving and Cloud operations
usually require less effort than on-premise IT operations. Cloud transitions, however, increase the
risk and audit team’s responsibilities, knowledge, and skills requirements. How do you see SMEs
changing their risk and audit teams to adapt to Cloud environments? Please select all that apply.
Answer Choices Responses Count
Increase size and budget of risk and audit teams. 41.18% 7
Reorganize or change structure of risk and audit teams 64.71% 11
Increase outsourcing or use of consultants to perform Cloud risk and
audit duties.
47.06% 8
Increase workload of existing risk and audit teams. 76.47% 13
Research question 2. What are the primary categories of concern presently being
addressed in Cloud specific risk assessments?
Every respondent to survey one saw non-technical areas of concern and IT (not security)
areas of concern for SMEs transitioning to the Cloud. Several survey questions directly
addressed research question two, including survey one, questions fourteen, fifteen, sixteen, and
seventeen. The two tables following, show the responses to questions fifteen and seventeen.
Every respondent to survey one saw non-technical areas of concern for SMEs transitioning to the
Cloud, with the majority of those concerns being privacy, business process, governance,
financial, or legal related. Respondents see more than one non-technical area of concern for
90
SMEs. Majorities of survey one respondents saw IT team knowledge and skills, IT audit results,
type of Cloud to use, network path to Cloud, backup and restore, and cost as primary categories
of concern in Cloud risk assessments. A plurality of respondents to survey one, question fifteen
and question seventeen selected every response except other.
Respondents to the second survey found a large number of non-IT related concerns for
SMEs when transitioning to the Cloud. While there was no one specific concern with a majority
of respondents, there were ten concerns with a third or more respondents selecting them. Survey
two, question thirteen added additional choices of concerns including business process and risk
assessment. Survey two, question thirteen also included choices specific to outsourcing the
concerns listed in survey one, questions fourteen through seventeen. These results reinforce the
major them of this research study. SMEs need more Cloud expertise and if it is not present in
existing staff, one solution is to use a competent third-party to help.
Table 5
Survey 1, Q15: What non-technical areas of concern do you see when SMEs are contemplating
Cloud adoption?
Answer Choices Responses Count
Governance 80% 16
Business Process 85% 17
Financial (non-technical) 70% 14
Privacy 85% 17
Legal 55% 11
Other 15% 3
91
Any additional comments (We want your expertise)? 15% 3
Table 6
Survey 1, Q17: What IT (non-security) areas of concern do you see for SMEs as they adopt
Cloud computing? Please select all areas of concern that you have seen.
Answer Choices Responses Count
Backup and Restore 60% 12
IT Audit Results 75% 15
Transition Process to Cloud 100% 20
Type of Cloud to use IaaS (Infrastructure as a Service), PaaS
(Platform as a service), SaaS (Software as a service)
70% 14
IT Team Knowledge and Skills 75% 15
Network Path to Cloud (redundant paths, multiple Internet service
providers)
65% 13
Cost 55% 11
Psychological Barriers/Concerns 50% 10
Other 0% 0
Other (please specify) 5% 1
Based on what SMEs pay attention to when starting the transition to the Cloud,
respondents to survey two report that a strong majority see the choice of a CSP and then the
choice of the type of Cloud infrastructure as primary concerns. SMEs make these choices before
92
the SME would normally conduct a risk assessment process. Researchers would need to conduct
further research before concluding that the SME risk assessment team was involved with
choosing a particular Cloud vendor or Cloud computing infrastructure. Almost half of survey
two respondents see choice of security controls and choice of Cloud security baselines as primary
concerns.
Table 7
Survey 2, Q8: When starting to plan a transition to a Cloud environment, what have you seen
SMEs start with before risk assessments or collections of requirements? Please select all that
apply.
Answer Choices Responses Count
Choice of CSP (Cloud service provider). 86.96% 20
Choice of infrastructure such as IaaS (Infrastructure as a Service),
PaaS (Platform as a Service), or SaaS (Software as a Service).
69.57% 16%
Choice of IT framework such as COBIT, ITIl, or ISO/IEC 38500. 30.43% 7%
Choice of security control standards such as NIST SP 800-53 or CSF,
HIPAA, or PCI-DSS.
47.83% 11
Choice of Cloud security baselines such as FedRAMP, CIS, or CSA. 47.83% 11
Automation tools such as DevOps or DevSecOps. 26.09% 6
Other 4.35% 1
The responses to survey three, question ten indicate that a lack of current SME IT staff
expertise is a major concern for SMEs in survey one. In survey two, the researcher asked
participants several questions in an attempt to identify the cause of a lack of staff expertise and
93
possible solutions. In response to survey two, question eleven a majority of respondents
identified multiple causes including IT staffs that are undersized, budget deficiencies, governance
and management issues, and SME business structure. Again, this points to the predominant
theme of this research; SMEs do not have enough Cloud expertise on staff.
In response to survey two, question twelve risk experts identified several solutions with a
preponderance of choices using third parties or outside consulting. If a SME is outsourcing its
operations and on-premises hardware to a CSP, it may make sense to include all facets of a
Cloud computing operation (Fahmideh & Beydoun, 2018). Outsourcing is certainly an option for
SMEs in other business operations (Al-Isma'ili, Li, Shen, & He, 2016; Baig, Freitag, Moll,
Navarro, Pueyo, Vlassov, 2015), outsourcing a Cloud transition may be the best way to address
Cloud specific risk concerns (Fahmideh & Beydoun, 2018). Survey two, question fifteen
attempted to correlate SMEs choices of CSP to help address research question two. The choice
of CSP could help inform primary categories of concern because CSPs offer different services,
security offerings and control choices.
Respondents to survey two, however, selected CSPs at a rate very similar to the general
publics’ usage of CSPs and Cloud offerings. No respondent picked a specialty CSP aside from
Oracle Cloud. Responses to survey two, question fifteen may be related to the lack of IT staff
training and knowledge shown in responses to survey two questions. Further study on this topic
may be fruitful. Respondents to survey three showed by their choices to answer question ten that
SMEs were making changes to address primary categories of concern identified in previous
survey questions even if the choice of CSP does not indicate a meaningful trend. Majorities of
respondents choose new IT controls, Cloud security guides, IT governance frameworks, and CSP
recommended practices as ways in which SMEs were addressing primary categories of concern.
94
A researcher can show that the responses to this correlate with previous questions that show
outsourcing as a primary tool to alleviate a lack of staff Cloud expertise but that is not a
conclusion drawn from this research.
Table 8
Survey 3, Q10: When assessing risk of Cloud environments, do you see SMEs changing their
process in the ways listed below? Please select all that apply.
Answer Choices Responses Count
Using CSP recommended practices 55.56% 10
Using any IT governance frameworks not previously used by the
SME.
61.11% 11
Using any IT controls not previously used by the SME. 77.78% 14
Using any Cloud security control guides not previously used by the
SME.
61.11% 11
Other (Please describe) or any additional comments (We want your
expertise)?
0% 0
Research question 3. What are the commonly used and tailored security controls in
Cloud specific risk assessments?
For the purpose of this research study the definition of Cloud security controls does not
have great specificity. Although security control catalogues abound, and include great detail in
every part of applying and using a particular security control, the goal of this research study is
not to pick individual controls. As a practical matter, asking survey respondents to go through
95
thousands of individual controls was not feasible. Asking respondents about control families is
the proper level of detail for this research study.
Almost all respondents to survey one have seen security controls used in Cloud risk
assessments and almost all respondents to survey one see SMEs adopting Cloud security
controls. These are similar questions with a difference in tense. The underlying requirement for
research question three is that SMEs are using security controls in Cloud computing
environments. A large majority of respondents to survey one selected all choices for IT security
controls by large majorities except for CIS top twenty controls with just over fifty per cent
selection and two control families; IEC 62443 and ENISA with less than sixteen per cent. Based
on the percentages of selection by respondents, SMEs are using many different security controls.
96
Table 9
Survey 1, Q11: What IT security control standards do you see SMEs using? Please select the
standards from the list below.
97
Answer Choices Responses Count
CIS (Center for Internet Security) top 20 controls 52.63% 10
NIST SP 800-53 (National Institute of Standard and Technology
Special Publication 800-53 Security and Privacy Controls for
Information Systems and Organizations)
84.21% 16
NIST Cybersecurity Framework (National Institute of Standard and
Technology)
84.21% 16
ISO/IEC 27001 (International Organization for
Standardization/International Electrotechnical Commission
Information Security Management Systems)
73.68% 14
IEC 62443 (International Electrotechnical Commission Industrial
Network and System Security)
5.26% 1
ENISA NCSS (European Union Agency for Network and
Information Security National Cyber Security Strategies)
15.79% 3
HIPAA (Health Insurance Portability and Accountability Act) 78.95% 15
PCI-DSS (Payment Card Industry Data Security Standard) 68.42% 13
GDPR (General Data Protection Regulation) 78.95% 15
Other 5.26% 1
Respondents to survey one selected all choices for Cloud security controls in question
nineteen. There is a clear split with newer control choices such as CASB or SecaaS under fifty per
98
cent, and older tools such as virtual firewalls and physical security devices receiving closer to
seventy per cent. This is a very interesting question for future research. As DevOps and
DevSecOps becomes more prevalent in IT, this balance may change (Betz & Goldenstern, 2017).
Cloud computing cannot realize its full power until SMEs start adopting Cloud specific tools and
paradigms. The use of DevOps and DevSecOps would help address the main theme of this
research. If SMEs adopted newer Cloud processes and procedures, SME IT staff would be able
to raise their Cloud expertise.
99
Table 10
Survey 1, Q 19: What Cloud security controls do you see SMEs adopting? Please select all
Cloud security controls that you have seen.
100
Answer Choices Responses Count
Data storage 68.42% 13
VMs (Virtual Machines) 57.89% 11
Micro services (Docker, Kubernetes, etc.) 31.58% 6
Networks 52.63% 10
Virtual security devices (for example; virtual Firewalls or Amazon
Web Services (AWS) security groups)
73.68% 14
Physical security devices (for example; a Hardware Security
Module (HSM))
57.89% 11
CASB (Cloud Access Security Broker) 21.05% 4
Encryption at rest 78.95% 15
Encryption in transit 89.47% 17
Encryption during compute (homomorphic encryption) 31.58% 6
Backup 52.63% 10
SecaaS (Security as a Service) 31.58% 6
SecSLA (Security Service Level Agreement) 15.79% 3
IAM (Identity and Access Management) 63.16% 12
MultiCloud 15.79% 3
Other 0% 0
101
Common across the three surveys, respondents agree with the idea that outsourcing or
using a third party for all or parts of a SME’s Cloud transition is a proper solution in many cases,
again supporting the major theme of this research. Outsourcing the entire Cloud transition is a
common way for SMEs to enact Cloud controls. Survey respondents also see recommendations
to outsource the planning of transferring data to the Cloud as a commonly used security step for
Cloud transitions. When looking at moving further down into the process of transitioning to a
Cloud computing environment, the pattern of outsourcing continues. For example; less than half
of the respondents have seen recommendations to have the SME IT team execute specific Cloud
security controls, Similar to the concept of DevOps and DevSecOps transforming Cloud
environments and Cloud security tools, a future research project may find outsourcing diminish
as SME IT teams become more conversant in DevOps and DevSecOps (Fahmideh & Beydoun,
2018). As outsourcing or the use of a third party is so prevalent, SMEs may not focus on tailoring
and using Cloud security tools.
Table 11
Survey 2, Q10: 100% of respondents to Survey 1 have seen recommendations to outsource the
transition to a Cloud environment. Which portions of a transition to a Cloud environment have
you seen recommended to be outsourced? Please select all that apply.
Answer Choices Responses Count
Entire transition including choice of CSP (Cloud Service
Provider), type of virtual environment, and transfer of data.
15.79% 3
Selecting CSP and type of infrastructure such as IaaS, PaaS, or
SaaS.
47.37% 9
Creating and executing data transfer plan to Cloud environment. 68.42% 13
102
Creating and executing security controls in Cloud environment. 42.11% 8
Managed or professional services including ongoing management
of SME data and IT operations.
73.68% 14
Managed security services including scheduled audits or penetration
testing.
42.11% 8
Other. 0% 0
Respondents to survey two, question sixteen show a similar pattern to survey two, question
six in that many SMEs are using Cloud tools but a smaller percentage are also auditing the
tools. Survey three, question seven respondents recognize new hazards that need controls by a
large margin for CSP environments. This raises the issue of how SMEs are using and tailoring
Cloud security controls again. If SMEs are not auditing or risk assessing Cloud tools and Cloud
environments, then SMEs are most likely not tailoring controls based on specific threats.
As shown by the replies to survey three, question eleven, SMEs see a shift in standard
risk practice when transitioning to the Cloud. Respondents see risk assigned to business owners
less than forty per cent of the time. Respondents see the SME security team assigned the risk
almost as often. This is a change from usual SME practice (Brender & Markov, 2013). Perhaps
this shift is a result of more outsourcing and use of third parties but only more research can
confirm this hypothesis. This may be a tangential theme to that of Cloud outsourcing or just an
indication of SMEs not truly understanding Cloud computing.
The responses to survey three, question twelve split evenly on accepting CSP based
controls. A strong plurality or respondents see SMEs using new IT governance controls and
103
Cloud security control guides. SMEs are using new security controls as they transition to a Cloud
environment but this research study results do not show that SMEs have reached the point where
SMEs are tailoring Cloud security controls for specific risks. Again, as SMEs adopt Cloud
specific paradigms and tools such as DevOps and DevSecOps, this may change.
A majority of survey three, question thirteen respondents see SMEs integrating new
Cloud security controls into existing control catalogues. Over a third of respondents are reporting
that SMEs are keeping Cloud controls separate. Perhaps the use of “tailoring” in research
question three seems imprecise or used too early in the general SME Cloud adoption process.
Some current research suggests that DevOps and DevSecOps, among other changes, may
revolutionize Cloud security control changes and allow continuous security control changes
(Betz & Goldenstern, 2017). Revisiting research question three in five to ten years may show
very interesting results.
Table 12
Survey 3, Q 13: Once controls have been identified for the SME’s environment, what effect do
they have on existing SME IT controls? Please select all that apply.
Answer Choices Responses Count
New Cloud controls are kept separate from existing control
catalogues.
35.29% 6
New Cloud controls are combined with existing controls to form
larger control catalogues.
64.71% 11
New Cloud controls promise to replace or reduce existing control
catalogues spurring increased Cloud transitions.
17.65% 3
104
New Cloud controls appear onerous and reduce Cloud transitions
due to increased difficulty.
5.88% 1
Other (Please describe) or any additional comments (We want your
expertise)?
5.88% 1
Research question 4. What are the commonly recommended mitigations in Cloud
specific risk assessments?
As shown by the responses to survey one questions, all respondents have seen
recommendations to outsource at least a portion of the SMEs transition to the Cloud. Survey one
respondents have not seen a risk assessment recommendation to avoid Cloud computing. A
majority of survey two respondents see SMEs receive recommendations to mitigate Cloud risk
by outsourcing the transition or planning the details of the data transition. A majority of survey
respondents have seen multiple recommendations such as accept CSP attestations, accept CSP
SLAs, and outsourcing of Cloud operations. These results reinforce the main theme of this
research. If SMEs do not have enough well-trained Cloud staff, the SME may make poor
decisions such as blindly accepting CSPs’ initial SLAs and attestations.
Survey two respondents did not converge on any particular mitigation to non-IT related
concerns for a Cloud transition with most respondents selecting several concerns. A majority of
respondents to survey three, question eight and nine see Cloud risk assessments changing SME
mitigation and risk avoidance procedures with changes in Cloud mitigation and risk strategies
and procedures predominant. There does not appear to be an actionable recommendation from
these two questions rather than devout more attention to GDPR. While one could argue that
105
perhaps a SME would not need to worry about the effects of GDPR on their business if the SME
did not adopt Cloud computing, this does not appear to be a Cloud specific mitigation.
If one considers accepting CSP attestations, SLAs, and guidelines as third-party guidance,
a preponderance of survey respondents report seeing recommendations to outsource at least part
of the SME’s Cloud transition. Responses to survey three, question six show that a majority of
respondents to survey three have accepted that contracting outside help is an appropriate
mitigation. Mitigating Cloud risk involves adding Cloud expertise to the SME or the SME should
consider outsourcing Cloud risk assessments. Again, an almost overwhelming amount of coding
done in this research study leads to the central theme of SMEs lacking competent Cloud staff.
Discussions related to research question two and three detail some of the reasons for the
outsourcing or consulting recommendations. Only a small portion of respondents to survey two,
question ten have seen recommendations to outsource the entire Cloud transition process. A large
majority of respondents, however, have seen recommendations to use managed or professional
services including ongoing management of SME data and IT operations. A similar majority have
seen recommendations for outsourcing the creation and execution of a data transfer plan to the
SMEs Cloud environment. Close to half of the respondents have seen recommendations for
SMEs to outsource the selection of a CSP and type of infrastructure such as IaaS, PaaS, or SaaS.
Almost half responded affirmatively to the use of managed security services including scheduled
audits or penetration testing. Reinforcing the central theme of the research results, it seems clear
by the data collected in this research study that the most commonly recommended mitigation in
Cloud specific risk assessments is to outsource at least part of the transition to the Cloud process.
106
Table 13
Survey 2, Q10: 100% of respondents to Survey 1 have seen recommendations to outsource the
transition to a Cloud environment. Which portions of a transition to a Cloud environment have
you seen recommended to be outsourced? Please select all that apply.
Answer Choices Responses Count
Entire transition including choice of CSP (Cloud Service Provider),
type of virtual environment, and transfer of data.
15.79% 3
Selecting CSP and type of infrastructure such as IaaS, PaaS, or SaaS.
47.37% 9
Creating and executing data transfer plan to Cloud environment. 68.42% 13
Creating and executing security controls in Cloud environment. 42.11% 8
Managed or professional services including ongoing management
of SME data and IT operations.
73.68% 14
Managed security services including scheduled audits or penetration
testing.
42.11% 8
Other. 0% 0
Evaluation of the Findings
The results of this research study both agree and extend current research in the field yet
disagree in some instances. SMEs understand what Cloud computing is and show a good
knowledge of what different types of Cloud services are available. As previous research has
found, SMEs are not well prepared for secure transitions to the Cloud (Lacity & Reynolds, 2013;
107
Mohabbattalab, von der Heidt, & Mohabbattalab, 2014). While previous research has done a
good job identifying security issues for SMEs adopting Cloud computing, most of the proposed
solutions are not currently in use by SMEs based on the respondents to this research study. This
study shows that SMEs are not yet using well prepared or defined plans to mitigate Cloud
computing risks.
Regarding research question one, this research shows no convergence in attempts by
SMEs to use large enterprise solutions such as recognized IT frameworks, Cloud security
baselines, or Cloud control guidelines or families. This research study confirms earlier research
indicating that SMEs have taken a piece meal approach to Cloud computing with most SMEs
using at least one Cloud service without necessarily conducting a risk assessment on that service
(Al-Isma'ili, Li, Shen, & He, 2016; Bassiliades, Symeonidis, Meditskos, Kontopoulos, Gouvas,
& Vlahavas, 2017; Famideh & Beydoun, 2018; Shkurti, & Muça, 2014). Based on this research,
SMEs are not doing a good job auditing or risk assessing new Cloud environments. A finding
from this research is that SMEs are more likely to outsource or use third parties to conduct Cloud
transitions than previous research has shown. This research study expands on current research by
showing that a lack of competent Cloud trained staff is the genesis of most of these behaviors.
Until SMEs have more in-house Cloud expertise, their use of Cloud related frameworks will be
lacking.
Regarding research question two, this research study agrees with earlier research that
shows SMEs have a variety of concerns with Cloud computing that are non-technical based
(Senarathna, Wilkin, Warren, Yeoh, & Salzman, 2018). This research shows a lack of SME staff
preparedness and training budget for transitioning to the Cloud is the primary concern for SMEs,
building upon earlier research that lists this as one of a number of concerns (Fahmideh &
108
Beydoun, 2018). Again, this study shows SMEs turning to outsourcing or third parties to solve
this issue. The results of this study show that SME risk teams are trying to adapt to Cloud
computing in a variety of ways but the risk teams see an increasing work load in almost all cases.
This research study is one of the first to report on how risk teams are changing due to new Cloud
computing environments. Results of this research show that SMEs and SME risk teams are not
keeping up with the new demands of Cloud computing and the required mitigations. This study
shows that aside from outsourcing or using third parties to perform parts or all of the SME
transition to the Cloud, SMEs are not showing proper oversight of their Cloud environments.
SMEs are accepting CSP attestations and SLAs in large percentages, something they would not
allow their risk teams to do with other vendors. This research extends previous research that
shows SMEs are not prepared for a transition to the Cloud with more insight on the details
(Kumar, Samalia, & Verma, 2017; Moyo & Loock, 2016; Vasiljeva, Shaikhulina, & Kreslins,
2017). The primary theme of this research study’s data is the lack of well-trained SME Cloud
teams, this seems to include the risk and audit teams also.
Regarding research question three, this research study shows that SMEs are not using best
practice or Cloud specific security tools in any large margin. Most respondents are either using
old non-Cloud specific security control guidelines or using third parties to select and apply
controls. The central theme of a lack of well-trained Cloud IT staff presents itself in these results
too. Perhaps a Cloud feedback loop of SMEs using true Cloud tools and controls such as DevOps
or DevSecOps will produce skilled Cloud staff who will then use more Cloud specific tools and
controls.
Regarding research question four, this research study follows the central theme that SMEs lack
proper Cloud trained staff which affects the recommended mitigations from SME Cloud risk
109
assessments. Based on the lack of internal Cloud staff, a large majority of risk professional
respondents have seen mitigation recommendations to outsource part or all of a Cloud transition.
This includes using managed or professional services for data transfer plans, CSP selection,
infrastructure selection, ongoing management of SME data and IT operations, even the risk
assessments and audits themselves.
Summary
Data collection for this qualitative research study consisted of a three-round survey of
GWDC risk experts. This chapter has established the trustworthiness of the data including how
credibility, dependability, and confirmability. This chapter has described the reasons and
assumptions made that led to keeping participation in the survey instruments anonymous and
collecting very little demographic detail. This chapter has organized the results of the research
study by research question. The questions in the survey instruments were multiple choice and
presentation of the data in this chapter includes tables as appropriate. The use of a Delphi
technique based three round survey instrument has resulted in data that answers the four research
questions of this study.
The answer to research question one is that SMEs using insufficient or non-Cloud
focused frameworks when risk assessing Cloud computing. The answer question to research
question two is that the primary concern for SMEs in Cloud specific risk assessments is the lack
of qualified SME Cloud and Cloud security teams. The answer question to research question
three is that SMEs commonly use a wide range of security controls and SMEs have not
converged on a particular process or set of controls to secure Cloud computing environments.
The answer question to research question four is that SMEs do not yet have a common set of
recommended mitigations for SME Cloud computing risk assessments. SMEs are still relying on
110
CSPs and existing frameworks, security guides and control families for mitigation
recommendations. SMEs are not at the point where the SME risk team can produce specific clear
and effective mitigation steps.
An additional result of this research study is a validated survey instrument that SMEs can
use to gauge their risk and needed next steps in the SMEs transition to the Cloud. The instrument
will be a freely available survey on SurveyMonkey. The page logic of the survey will help guide
SMEs to consider the answers to this research studies questions and how the SME can move
forward securely. While the survey instrument will not replace a full-fledged risk assessment, the
survey instrument will help guide SMEs to making more informed decisions at the start of the
SMEs’ Cloud transition. The survey questions and link to the survey are in the Appendix E.
Chapter 5: Implications, Recommendations, and Conclusions
The researcher used this qualitative cased study based research project to address the
problem that there is no commonly understood and adopted best practice standard for small to
medium sized enterprises (SMEs) on how to specifically assess security risks relating to the
Cloud (Coppolino, D’Antonio, Mazzeo, & Romano, 2016; El Makkaoui, Ezzati, Beni-Hssane, &
Motamed, 2016; Raza, Rashid, & Awan, 2017). Research in IT fields has a hard time keeping up
with real world applications due to the high rate of change in the industry. This issue increases
almost exponentially when one focuses on Cloud computing security. Many research studies
have taken the first step and identified risk-based organizational concerns with Cloud computing
security, and a few authors have proposed novel solutions. Evidence of what organizations are
doing to satisfy their risk requirements in Cloud computing adoption is not clear.
The purpose of this qualitative case study-based research study was to discover an
underlying framework for research in SME risk analysis for Cloud computing and to create a
111
validated instrument that SMEs can use to assess their risk in Cloud adoption. Unlike SMEs, the
vast majority of medium to large enterprises use risk assessments before adopting new
computing environments (Cayirci, Garaga, Santana de Oliveira, & Roudier, 2016; Jouini &
Rabai, 2016). SMEs need a process or validated instrument such as a risk assessment to
determine if they should move to the Cloud (Bildosola, Rio-Belver, Cilleruelo, & Garechana,
2015; Carcary, Doherty, & Conway, 2014; Hasheela, Smolander, & Mufeti, 2016). Research
shows that SMEs using a risk-based approach have not reached a consensus on how to identify
and address Cloud security risks (Carcary, Doherty, Conway, & McLaughlin, 2014; Kumar,
Samalia, & Verma, 2017). The creation of a new framework for academic treatment of SME
Cloud computing risk, and the creation of a validated instrument that SMEs can use to assess
their risk in Cloud adoption were the reasons for this research study.
A qualitative approach using a case study methodology was the best solution as the theory
relating to a successful Cloud computing risk assessment does not yet exist. A problem avoided
by using a qualitative case study approach is that the subject population of risk-based Cloud
computing research experts were able to respond with qualitative data but not quantitative
numbers to avoid compromising their organization’s security (Glaser, 2014). Making sure to limit
the subject population to subject matter experts allowed the researcher to create very specific
survey instruments. This helped eliminate potential areas of bias or confusion for participants.
Even though the audience for this research study commonly works in quantitative ways, the
audience will find value in qualitative case study research on this topic (Liu, Chan, &
Ran, 2016).
112
A survey with a Delphi technique of industry experts was an effective way to both
resolving those concerns of SMEs adopting Cloud computing and was a good step to increasing
the knowledge in the academic field of Cloud security. The RAND Corporation created the
Delphi technique to facilitate the collation and distillation of expert opinions in a field (Hsu &
Sanford, 2007). The Delphi technique seems well designed for the Internet with current
researchers using “eDelphi” based web surveys (Gill, Leslie, Grech, & Latour, 2013). Although
Cloud security is a very new field, some illustrative research is evident in the field using Delphi
techniques (Choi & Lee, 2015; El-Gazzar, Hustad, & Olsen, 2016; Liu, Chan, & Ran, 2016).
These studies use the Delphi technique in different manners, but similar to this proposed research
study, all rely on electronic communications with groups of experts.
The guiding framework of this research study was that the risk assessment process for
Cloud computing environments is fundamentally different for SMEs than large enterprises and
the primary data collection instrument is a web survey of risk experts with a Delphi technique.
The population for this research study has constraints on security information that they can share.
A qualitative case study-based theory approach was an effective way for the researcher to gather
the data needed to propose a unifying theory for SME Cloud computing risk assessment. As the
state of research in SME risk assessment tools and procedures is still in the nascent stages, case
study-based theory is the correct framework to advance the field and to create a validated
instrument for SME Cloud computing risk assessments.
The design of this research study evolved from the need to find out what was actually
happening in Cybersecurity Cloud risk assessments, a very specialized and secretive field. A
qualitative case study approach using a Delphi instrument was the research design chosen for this
research study. The researcher created a web-based survey with three rounds composed primarily
113
of multiple-choice questions to work around the strictures normally placed on cybersecurity
professionals. The researcher choose a very focused and small population of cybersecurity risk
experts in the Washington D.C. area. The researcher asked subjects to participate in three
webbased surveys over a period of five months. The researcher posted links to the surveys on the
GWDC web site and promulgated through GWDC emails and conferences.
The three rounds of responses from cybersecurity risk experts provided the researcher
with answers to the research questions posed by this study. The researcher was able to identify
current frameworks being leveraged in Cloud computing risk assessments. The researcher has
determined the primary areas of concern for SMEs as they transition to the Cloud. The researcher
has generally identified the commonly used security controls recommended in Cloud computing
risk assessments. The researcher has brought to light mitigations that risk professionals associate
with a SME transition to Cloud computing.
Limitations of this research study are based on the secrecy of information in the
cybersecurity field and the limited subject population that can provide useful information.
Organizations do not share security data including defense designs, breaches, and policies and
procedures. Potential survey questions for this research had to balance the need for pertinent
information and the limited ability of respondents to share specific information. The subject
population for this research question was a very small subset of IT professionals and the
researcher needed to do a large amount of preliminary work to gain access to an appropriately
sized group of respondents.
In this chapter, the researcher reiterates the problem statement, purpose statement,
methodology, design, results, and limitations. The researcher continues with the implications
from the results of this research study organized around the research questions. Following the
114
discussion of implications, the researcher presents recommendations for practice and future
research. The last section of this chapter is a conclusion.
Implications
The implications derived from this research study are best discussed by research
questions. The researcher focused research question one on the current state of Cloud computing
risk assessments and what frameworks SMEs are currently using. Based on the response to the
survey questions, predominately survey two questions, the current state of Cloud risk
assessments has not kept up with the changes in business and IT brought on by Cloud computing.
This is consistent with most Cloud transition research (Madria, 2016; Shackleford,
2016). Almost uniformly, SMEs are using Cloud computing without preforming complete risk
assessments on the Cloud tools and offerings as indicated by survey two, questions seven and ten
results. Previous research has not focused on this issue. Response to survey one, questions eight
and nine indicate that some SMEs are using large enterprise frameworks such as COBIT and
ITIL but SMEs are not showing a consensus on choice of frameworks based on survey. One
could infer this from current research but not definitely state it (Barton, Tejay, Lane, & Terrell,
2016; Tisdale, 2016; Vijayakumar & Arun, 2017). Government based Cloud security
configurations are being adopted more frequently than public sector ones, showing that if a SME
is compliance based, they are more likely to follow predetermined policies and procedures for
Cloud computing transition as per survey one, questions twelve and thirteen. This research study,
specifically survey two, question ten and survey three, question fifteen does indicate that SMEs
have almost uniformly considered outsourcing or using a third party to adapt a framework to
their Cloud transition. This is a strong amplification of previous research efforts that have
115
mentioned third parties or outsourcing as an option (Gupta, Misra, Singh, Kumar, & Kumar,
2017).
The researcher focused research question two on the primary areas of concern for SMEs
as they perform Cloud computing risk assessments. Most of the SMEs referenced by the survey
respondents do not start with a blank state. Responses to survey two questions seven and eight
show that most SMEs select a CSP and a type of Cloud infrastructure before the SME begins the
Cloud transition risk assessment process. This helps narrow the primary areas of concern for
SMEs to general IT concerns such as backups or network paths, and a wide array of nontechnical
concerns that confirms previous research in the field (Cheng & Lin, 2009; Diaz-Chao, Ficapal-
Cusi, & Torrent-Sellens, 2017; Lai, Sardakis, & Blackburn, 2015). Responses to survey one,
questions fourteen and fifteen shows that every respondent reports non-technical concerns for
SMEs that they work with. Almost all respondents indicate that governance, business process,
financial, and privacy concerns affect SMEs that are transitioning to the Cloud.
In Survey 2, responses to questions ten, eleven and twelve support the finding that by far
the biggest primary concern reported by this research study participants is that of the SMEs IT
staff knowledge levels and Cloud readiness. SMEs are also concerned with the reasons that the
SME IT teams are not ready, including; lack of training, IT staff budget, and IT staff resistance to
Cloud computing environments as per the responses to survey two, question eleven. Survey one,
question twenty-one and survey two, question ten shows that SMEs are overwhelmingly
outsourcing IT tasks related to the SME’s Cloud transition or using third parties for their Cloud
transitions.
The researcher asked with research question three; what are the commonly used security
controls used in Cloud risk assessments. Almost all respondents to survey one, question ten,
116
eleven, and eighteen see SMEs use security controls specific to Cloud environments. This
confirms earlier research in the field (Haines, Horowitz, Guo, Andrijicic, & Bogdanor, 2015;
Rahulamathavan, Rajarajan, Rana, Awan, Burnap, & Das, 2015; Sahmim & Gharsellaoui, 2017).
Responses to survey one, question nineteen bounds the type of controls being used by SMEs.
Newer Cloud specific controls and tools such as CASB, SecaaS, and multi-Cloud are not in
widespread use by SMEs while older security controls are. Previous research in the field confirm
these results by not generally discussing modern controls and discussing a lack of SME focus on
best practices for a Cloud transition (Gholami, Daneshgar, Low, & Beydoun, 2016; Salim,
Darshana, Sukanlaya, Alarfi, & Maura, 2015; Yu, Li, Li, Zhao, & Zhao, 2018). Responses to
survey two, question sixteen indicate that whatever Cloud tools SMEs are using, they are not
being fully audited leading to the conclusion that SMEs need more controls. Research in the field
indicate a lack of preparation by SMEs for Cloud transitions including the use of security
controls but this research helps shed light on the details of SMEs’ lack of preparation (Huang et
al., 2015, 2015; Wang & He, 2014). Responses to survey three, question seven show that SMEs
still need a lot of work in this area with only seventy-one per cent of the risk experts seeing a
change in Cloud risk assessment hazards identification. Responses to survey three, question
twelve and thirteen indicate that the SMEs realize they need new security controls even if they
are not using them yet. Previous research supports this conclusion with several studies reporting
that many SMEs see a Cloud transition as a way to increase the SMEs’ IT security (Lacity &
Reynolds, 2013; Mohabbattalab, von der Heidt, & Mohabbattalab, 2014).
The researcher asked with research question four; what are the commonly recommended
mitigations in Cloud specific risk assessments. The design of this question intended to elicit
slightly different responses than just controls or control families. The assumption made by the
117
researcher was that all respondents would see specific recommendations made to SMEs but
respondents to survey one, question twenty show only seventy-five per cent have seen
recommendations. Previous research in the field supports this conclusion but this research study
is the first to quantify the number of SMEs seeing specific Cloud recommendations (Assante,
Castro, Hamburg, & Martin, 2016; Hussain, Hussain, Hussain, Damiani, & Chang, 2017).
Responses to survey one, question twenty-one help detail the specific mitigations recommended
to SMEs with eighty per cent of respondents saying that they have seen recommendations to
outsourcing or use third parties. This is a reoccurring theme in the data collected in this research
study. Previous research hints at the use of outsourcing by SMEs but this research shows how
prevalent it has become (Fahmideh & Beydoun, 2018). Overall, survey respondents show that
SMEs are adopting mitigations specific to the Cloud environments and changes to the mitigation
process with risk assessment changes as indicated by responses to survey three, questions six,
eight and nine. While accepting that Cloud computing environments require new mitigations and
new mitigation processes may seem obvious, previous research has not focused on this to any
great detail (Mohabbattalab, von der Heidt, & Mohabbattalab, 2014). Responses to survey three,
questions six and eleven, indicate that changes in the make-up of risk assessment teams and SME
risk responsibility assignment will affect recommended mitigations.
The primary factor that may have influenced the interpretation of the results of this
research study is that all significant results emerged from responses to multiple choice questions.
Perhaps the researcher did not include important choices in the answer choices. The researcher
has included all survey questions and responses in an appendix so the reader can decide. The
researcher presents the survey question answers in percentages so interpretation of the results
gathered is straightforward.
118
Recommendations for Practice
The researcher has encapsulated recommendations for practice in the validated risk
assessment instrument in the appendix. The primary recommendation is that SMEs need to spend
more time preparing for a Cloud transition. Even though responses to survey one, question eight,
nine, and twelve show a strong majority of SMEs transitioning to the Cloud do some planning,
SMEs need to do much more planning. Current research supports this finding but does not offer
many details (Bildosola, Río-Belver, Cilleruelo, & Garechana, 2015; Gastermann, Stopper,
Kossik, & Katalinic, 2014; Lacity & Reynolds, 2013; Senarathna, Yeoh, Warren, & Salzman,
2016). The validated risk instrument presented in the appendix does not get to the level of
specific controls but focuses on the decisions that SMEs must make before moving servers or
data to a CSP. Responses to survey three, questions seven, twelve, and thirteen indicate SMEs
realize they need to put more effort into the Cloud transition process and a validated risk
instrument with a series of fairly simple questions should help shape that effort. Existing research
shows that many SMEs see a Cloud transition as a way to increase security (Lacity & Reynolds,
2013; Mohabbattalab, von der Heidt, & Mohabbattalab, 2014), this research study helps show
how the SMEs can achieve that goal. The findings from this research study do not solve all
SMEs’ problems with Cloud transitions, but if used as indicated by the validate risk instrument,
SMEs should have a smoother and more secure Cloud transition effort.
Recommendations for Future Research
The primary recommendation for future study is that more research should focus on how
SMEs plan for Cloud transitions. Current research does a good job of identifying why or why not
SMEs are adopting Cloud computing but current research does not identify how SMEs should
119
transition to Cloud computing. This research study has taken the first steps and identified the
current frameworks and primary areas of concern for SMEs as they adopt Cloud computing.
Extending the results of this research study, however, will require much more research. Adopting
Cloud computing is much more than just changing IT vendors or changing the type of servers
used by the SME. Adopting Cloud computing is a major paradigm shift for many SMEs that will
fundamentally change how SMEs do business and interact with each other and customers.
Based on results from this research study, specific fields of interest deserving more
research include several cross-domain topics. This research has shown that a primary concern for
SMEs during Cloud transitions is staffing. SMEs are trying to decide if it make sense to
outsource part or all of a move to Cloud computing. Pursuing research to help answer this
question may involve management theory, employee training, business risk analysis, and IT
among other research fields. Cloud computing is primarily a field in which IT and cybersecurity
researchers work. The results of this research study indicate several promising avenues of
research in IT and IT security fields. SMEs are not using modern Cloud based tools yet.
Research investigating what would it take to get SMEs to adopt a Cloud tool such as DevOps or
DevSecOps may show interesting results. If, as this research shows, SMEs are heavily using
third parties and outsourcing for the transition to the Cloud, further research on how that will
affect the IT and IT security fields will produce many topics. If SMEs adopt Cloud computing
with third parties in control, research on how the day to day operations of the SME would change
and could bear useful results. This research study indicates that the field of IT risk is changing as
a result of Cloud transitions. Research on how the field of IT risk adapts to Cloud computing
would be a very interesting research topic.
120
Conclusions
The researcher has only identified the issues for Cloud computing adoption by SMEs
from the perspective of risk experts. This research study has not identified ways in whcich those
risk experts can make the SME decision makers adopt these findings. Future research will need
to identify the answers and solutions that SMEs will adopt. Cloud computing is a very technical
field but this research study shows that SMEs’ biggest problems with transitioning to the Cloud is
human based, not technical. This research study builds on prior research and points the way for
future research. Earlier research has shown that SMEs show hesitation when moving to the
Cloud. Previous research studies have not identified the major concerns and road blocks for
SMEs as they transition to the Cloud. This research illuminates the major issues for SMEs
adopting Cloud computing.
This research study shows that SMEs are adopting Cloud computing in a piece-meal and
unorganized way. Future research on whether or not SMEs converge on best practices and
standards will be important work. As the use of Cloud computing is becoming an inflection point
for SMEs, SMEs need more research on both the process and the results. Cloud computing is
fundamentally changing the daily pace of business, and this research study shows that SMEs
have not kept pace. SMEs would greatly benefit from more research to help them adopt Cloud
computing securely and effectively.