Back to Search Start Over

MANAGING DATA SECURITY RISK IN MODEL SOFTWARE AS A SERVICE (SAAS)

Authors :
Nooraidaniza Jafri
Maryati Mohd Yusof
Source :
Asia-Pacific Journal of Information Technology and Multimedia, Vol 7, Iss 01, Pp 99-117 (2018)
Publication Year :
2018
Publisher :
UKM Press, 2018.

Abstract

Software as a Service (SaaS) model has been frequently applied in organisation that used cloud services. SaaS is a new Information Technology that provides dynamic services through Internet to the user. Alhough this technology is beneficial and cost-effective for information technology hosting, it also introduced new threats and risks, particularly in user's information security. The paper identifies risk in data security of the SaaS Model and their respective mitigation control based on ISO/IEC 27001:2013 standard. A qualitative case study was conducted at a public sector agency involving three types of data collection, interviews, observations and document analysis. We identified seven risk of data security for SaaS Model namely data privacy, data integrity, data availability, data control, data encryption, data violation, and data access. The findings can be used to develop SaaS implementation guidelines or policies, particularly in data security.

Details

Language :
English, Malay
ISSN :
22892192
Volume :
7
Issue :
01
Database :
Directory of Open Access Journals
Journal :
Asia-Pacific Journal of Information Technology and Multimedia
Publication Type :
Academic Journal
Accession number :
edsdoj.18a28bf0ed5544da9380402548cd8e0f
Document Type :
article
Full Text :
https://doi.org/10.17576/apjitm-2018-0701-09