Skip to main navigation Skip to search Skip to main content

Applicability of systems and software quality engineering methods and models to information security in cloud computing services

  • Jonathan Roy

Student thesis: Doctoral thesisDoctorate in Engineering: Engineering

Abstract

Industry continues to aggressively adopt cloud computing services, motivated by the potential benefits of their native characteristics. Additionally, information technology (IT) outsourcing experts consider security to be the most important non-functional requirement of cloud computing services. Consequently, a growing number of systems and software engineers must confront the quality engineering of cloud-based information systems (IS) to mitigate or avoid potential user or stakeholder risks. It has been well-established that the early application of quality engineering to IS development during requirement activities is a major milestone and contributor to building high quality IS. Furthermore, the application of quality engineering requires the use of a quality model with the capacity to support both the definition of quality requirements and their subsequent evaluation. However, the extent to which ISO/IEC 25000 quality models are applicable to information security in cloud computing services has not been identified. Accordingly, this thesis proposes the use of the ISO/IEC 25030 quality requirements framework as a systematic approach to answer the research question “To what extent do ISO/IEC 25000 quality models support the definition of quality requirements related to information security in cloud computing services?” Here, we use IS research design science practices to evaluate and extend the applicability of the ISO/IEC 25030 quality requirements framework to information security in cloud computing services. We also use the extended framework to answer the research question while illustrating its applicability to the quality requirement definition of cloud-based IS. Results from this thesis show that on the one hand ISO/IEC 25000 quality models cannot adequately mitigate the top threats to cloud computing services. On the other hand, the application of the extended framework demonstrates that these quality models can be tailored to the quality requirements definition of cloud-based IS for the purposes of mitigating or avoiding potential user or stakeholder risks.
Date12 May 2021
Original languageAmerican English
Awarding Institution
  • École de technologie supérieure
SupervisorWitold Suryn (Supervisor)

Cite this

'