Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Using a Capability Oriented Methodology to Build Your Cloud Ecosystem

Published

Author(s)

Michaela Iorga, Karen Scarfone

Abstract

Organizations often struggle to capture the necessary functional capabilities for each cloud-based solution adopted for their information systems. Identifying, defining, selecting, and prioritizing these functional capabilities and the security components that implement and enforce them is surprisingly challenging. This article explains recent developments by the National Institute of Standards and Technology (NIST) in addressing these challenges. The article focuses on the capability oriented methodology for orchestrating a secure cloud ecosystem proposed as part of the NIST Cloud Computing Security Reference Architecture. The methodology recognizes that risk may vary for cloud Actors within a single ecosystem, so it takes a risk-based approach to functional capabilities. The result is an assessment of which cloud Actor is responsible for implementing each security component and how implementation should be prioritized. A cloud Actor, especially a cloud Consumer, that follows the methodology can more easily make well-informed decisions regarding their cloud ecosystems.
Citation
IEEE Cloud Computing Magazine
Volume
3
Issue
2

Keywords

cloud, cloud computing, cloud architecture, standards, security, National Institute of Standards and Technology (NIST), risk management, risk management framework, risk assessment

Citation

Iorga, M. and Scarfone, K. (2016), Using a Capability Oriented Methodology to Build Your Cloud Ecosystem, IEEE Cloud Computing Magazine, [online], https://doi.org/10.1109/MCC.2016.38 (Accessed November 20, 2024)

Issues

If you have any questions about this publication or are having problems accessing it, please contact reflib@nist.gov.

Created March 31, 2016, Updated May 4, 2021