PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
April 16, 2026ACM Computing Surveys0 citationsOpen Access

Cloud Outsourcing Risk Management for Cloud Consumers: A Systematic Literature Review

View Full Paper
MHMuhammad Yasir Muzayan HaqSASiraj AnandLNL.J.M. Nieuwenhuis

Key Points

  • This review aims to explore risks and risk management techniques associated with cloud outsourcing for enterprise consumers.
  • Conducted a systematic literature review of 55 academic papers from January 2013 to September 2022.
  • Characterized risks using frameworks from ENISA and ISO31000.
  • Summarized 23 risk management strategies applicable to cloud consumers.
  • Identified a significant emphasis on technical risks, especially threats to data confidentiality.
  • Noted underrepresentation of non-technical risks like vendor lock-in and legal issues.
  • Highlighted encryption, auditing, and risk-aware software development as key management techniques.

Abstract

This systematic literature review explores the landscape of risks and risk management techniques in cloud outsourcing, with a focus on assisting enterprise cloud consumers in understanding and mitigating both technical and non-technical risks, despite having limited control over the infrastructures. From a comprehensive analysis of 55 academic articles, spanning the period from January 2013 to September 2022, we identify and characterize risks using established frameworks from ENISA and 20. Using ISO31000 and the classification proposed by 4, we also summarize and characterize 23 main strategies in risk management techniques feasible for cloud consumers, including technical and non-technical measures. We observe a significant emphasis on technical risks in the literature, while non-technical risks, including legal, organizational, and policy aspects, are relatively underrepresented. Threats to data confidentiality dominate the technical risks and mostly originate from shared infrastructure issues. However, non-technical issues, such as vendor lock-in, also pose catastrophic risks the continuity and business operations of the cloud consumers. We also observe that encryption still plays a key role in the existing techniques, next to other techniques such as auditing, risk-aware software development, and assessments of third parties.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Haq et al. (2026) studied this question.

synapsesocial.com/papers/69e07de52f7e8953b7cbeeb1https://doi.org/10.1145/3808691
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1Remote data possession checking with enhanced security for cloud storage2014 · 50 citations
  2. 2Security Concerns in Popular Cloud Storage Services2013 · 89 citations
  3. 3Towards a framework for trustworthy data security level agreement in cloud procurement2021 · 14 citations
  4. 4Millions of targets under attack2017 · 124 citations
  5. 5The economics of information security investment2002 · 1,333 citations