a. The Service Risk Assessment Process. Galactic
vulnerabilities are identified for the first time by
SWINSOFT with the help of GC who know the architecture
of the service and the hosting cloud platform. Both
SWINSOFT and GC have the responsibility to maintain the
service vulnerabilities list up to date. The framework
enables to synchronize the service vulnerabilities with the
community vulnerabilities database - NVD. Each CC –
Swinburne and Auckland – should review the defined
369threats and risks on Galactic and append any missing
threats. The framework integrates with the CWE and
CAPEC databases to help stakeholders in identifying
possible vulnerabilities whenever the service does not have
vulnerabilities recorded in the NVD