Högskolan i Skövde

his.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
SaaS Risk Management - a method for cloud supply chain risk assessment
University of Skövde, School of Informatics.
2025 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

Cloud computing has steadily increased in popularity in the last 20 years, with organizations increasingly choosing cloud-based solutions. However, cloud supply chains are associated with their own unique challenges and risks. Particularly within the Software-as-a-Service (SaaS) delivery model as a result of the shared responsibilities between several parties such as cloud service providers, hosting infrastructure providers, and cloud customers. Current industry tends to choose non-cloud specified information security risk assessment methods, despite the existence of cloud-specified standards. In parallel, the regulatory landscape of the European Union is changing with acts such as the Cybersecurity Act. This research conducts two iterations of the Design Science Research paradigm to develop a proposed method for cloud supply chain risk assessment. The proposed method aims to solve the challenges mentioned above by synthesizing existing knowledge within academia and industry to create a novel approach. The result identified several activities, resources, and processes for Information Security Risk Assessment (ISRA) in the cloud supply chains, namely supply chain mapping, data criticality assessments, data flow identification, and multi-consequence analysis. Data collection included several methods, such as systematic literature review, interviews with stakeholder experts, workshops to apply the method in a real-world context, and evaluation frameworks for method benchmarking. This study identified key cloud supply chain information security risks and five key design objectives for ISRA, namely applicability, compatibility, relevance, clarity, and transferability. Lastly, the study contributes to several academic discussions, such as difficulties in reliance on historical data, difficulties in quantifying probabilities, addressing the limitations of generic ISRA methods such as ISO/IEC 27005, and showed a limitation in inflexible risk formulas when aiming to achieve interoperability.

Place, publisher, year, edition, pages
2025. , p. 93
Keywords [en]
Risk Management, Information Security Risk Assessment, Cloud Supply Chain, ENISA Cloud Services Scheme, Design Science Research, Cloud Information Security Risks
National Category
Computer Systems
Identifiers
URN: urn:nbn:se:his:diva-25835OAI: oai:DiVA.org:his-25835DiVA, id: diva2:1998432
Subject / course
Informationsteknologi
Educational program
Privacy, Information and Cyber Security - Master's Programme 120 ECTS
Supervisors
Examiners
Available from: 2025-09-16 Created: 2025-09-16 Last updated: 2025-09-29Bibliographically approved

Open Access in DiVA

fulltext(854 kB)295 downloads
File information
File name FULLTEXT01.pdfFile size 854 kBChecksum SHA-512
0dd03553a2771e5dffce39550de6d80042195b3a6dcf4df4ebb0db2c7a85648a750153c3c8854701ff7942af65e4343c856e6514f13a3141fd4b1666396d1f70
Type fulltextMimetype application/pdf

By organisation
School of Informatics
Computer Systems

Search outside of DiVA

GoogleGoogle Scholar
Total: 296 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 338 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf