B. Cloud security management
Saripalli et al [10] proposed a quantitative risk analysis and
assessment method based on NIST- FIPS-199 [5]. Risk
assessment is a step in the SMP. The remaining steps of the
SMP are still required, as explained in section II. Although
the authors proposed a quantitative method in assessing
risks, they used qualitative evaluation bands (Low, Medium,
and High). Similar efforts were carried out by Xuan et al
[11]. ISO27000 [6], NIST-FISMA [12] are the two main