Data security services, solutions and standards for outsourcing

نویسندگان

  • Kevin W. Hamlen
  • Bhavani M. Thuraisingham
چکیده

a r t i c l e i n f o Keywords: Web services Access control Inference control Identity management Mobile code security Globalization has resulted in outsourcing data, software, hardware and various services. However, outsourcing introduces new security vulnerabilities due to the corporation's limited knowledge and control of external providers operating in foreign countries. Security of operation is therefore critical for effectively introducing and maintaining these business relationships without sacrificing product quality. This paper discusses some of these security concerns for outsourcing. In particular, it discusses security issues pertaining to data-as-a-service and software-as-a-service models as well as supply chain security issues. Relevant standards for data outsourcing are also presented. The goal is for the composite system to be secure even if the individual components that are developed by multiple organizations might be compromised. Data has become a critical resource in many organizations, including efficient data access, data sharing, data mining, and their applications for effective decision-making. Data and information must be protected from unauthorized access as well as malicious corruption. The advent of the World Wide Web (WWW) in the mid 1990s has resulted in even greater demand for managing data, information and knowledge effectively. There is now so much data on the web that managing it with conventional tools is becoming almost impossible. For example, Google's indexing system stores tens of petabytes of data with updates processed in parallel by thousands of machines per day worldwide [1]. These demands exceed the capabilities of traditional centralized operating systems and file systems, requiring new tools and techniques to effectively manage such large and dynamic data repositories. Web services are an important class of technologies that has emerged in recent years in response to this need. In service-oriented web architecture, data processing and other tasks that would otherwise need to be performed internally are shifted to external servers that communicate via standard web protocols. Typical examples of web services include making an airline reservation or filing an income tax return, both of which can be carried out by external service providers with a small amount of communication overhead from the service recipient. Globalization and various treaties such as NAFTA (North American Free Trade Agreement) and the founding of the European Union have resulted in increased outsourcing of data, software, hardware and various services. This is typically motivated by cost-cutting. For example, while it costs about $60 K plus benefits of about …

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

SESOS: A Verifiable Searchable Outsourcing Scheme for Ordered Structured Data in Cloud Computing

While cloud computing is growing at a remarkable speed, privacy issues are far from being solved. One way to diminish privacy concerns is to store data on the cloud in encrypted form. However, encryption often hinders useful computation cloud services. A theoretical approach is to employ the so-called fully homomorphic encryption, yet the overhead is so high that it is not considered a viable s...

متن کامل

Enforcing RBAC Policies over Data Stored on Untrusted Server (Extended Version)

One of the security issues in data outsourcing is the enforcement of the data owner’s access control policies. This includes some challenges. The first challenge is preserving confidentiality of data and policies. One of the existing solutions is encrypting data before outsourcing which brings new challenges; namely, the number of keys required to access authorized resources, efficient policy u...

متن کامل

Designing an Outsourcing Model for the Executive Organs of Mazandaran Province (Case Study of Health Networks of Mazandaran Province)

Background and Aim: Today, with the growth of government services and the increase in the workload of organizations due to population growth and increasing the number of citizens receiving services and the lack of government resources in providing manpower as well as the purchase of facilities and machinery The need has led executives to outsource services. Outsourcing is usually used as a way ...

متن کامل

Security Protocols for Outsourcing Database Services

Advances in networking technologies and the continued growth of the Internet have triggered a new trend towards outsourcing data management and information technology needs to external service providers. As a recent manifestation of this trend, there has been growing interest in outsourcing database services in both the commercial world and the research community. Although the outsourced databa...

متن کامل

Interpretative-Structural Modeling of Outsourcing Human Resources in Maroon Petrochemical Company

The research purpose was to identifying a model of factors affecting human resource outsourcing (HRO) in Maroon Petrochemical Company. The research is considered practical in terms of purpose and descriptive-exploratory based on mixed method, in terms of data collection. The statistical population was experts and experts of Maroon petrochemical company in the field of human resources. The numbe...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • Computer Standards & Interfaces

دوره 35  شماره 

صفحات  -

تاریخ انتشار 2013