1) Each stakeholder has their own SMP that they want to
maintain/extend to the cloud hosted assets.
2) No stakeholder can individually maintain the whole
security process of the cloud services because none of
them has the full information required to manage
security and each one has a different perspective.
3) Multi-tenancy requires maintaining different security
profiles for each tenant on the same service instance.
4) No Security SLA is available that can be used to
maintain agreements related to cloud assets security.
5) The existing standards such as ISO27000 and FISMA do
not map well to the cloud model because these standards
consider the SMP from the platform/asset owner not
from a Service Provider perspective.
E. Key requirements of the cloud ISMS
Any proposed security management framework for the
cloud model should cover the following key requirements:
1) Enable CCs to specify their security requirements on the
cloud hosted assets and the underlying cloud platform.
2) Enable CCs to monitor their assets security status and
the underlying platform security status as well.
3) Support for multi-tenancy where different tenants can
maintain their SMP with strong isolation of data.
4) Be based on existing security management standards that
are already adhered by the CCs and CPs.