A risk assessment framework for evaluating software-as-a-service (saas) cloud services before adoption
Monica S Bolesta, Lionel Bernard · 2011
Software-as-a-service (SaaS) is rapidly becoming the standard software platform for many organizations seeking to reduce their IT costs and take advantage of the inherent flexibility, quick deployment, ready access, and scalability of the SaaS concept. SaaS is part of the paradigm shift toward cloud computing in software, hardware, and IT services acquisition. Swayed by its noted benefits, SaaS adopters may neglect to consider the risks associated with SaaS and overall cloud-based services before adoption. SaaS risks stem from its multi-tenancy, Internet dependency, and the requirement to entrust cloud providers with confidential data. Existing standards for selecting commercial off-the-shelf (COTS) or custom-built software and frameworks for evaluating the risks of cloud-based services are either too broad to apply specifically to SaaS or do not take into account some of the unique requirements of SaaS. Furthermore, the issue of risk relevancy is significant if adopters are to formalize the SaaS decision-making process. A review of existing cloud risk assessment frameworks and cloud literature reveals higher-level risk dimensions of security, business continuity, and integration as the prevalent concerns regarding SaaS adoption. To determine the relevance of these risk dimensions, particularly to SaaS success, a web-based survey was conducted of organizational cloud decision-makers. The results provide evidence that certainty about some elements of security, business continuity, and integration significantly influences the adopting organization’s level of satisfaction with its overall SaaS experience. The findings serve as input to the development of a new SaaS-tailored risk assessment framework. The SaaS Cloud Risk Assessment Framework (S-CRA) is a questionnaire-based decision-making tool allowing cloud adopters to develop a risk profile of candidate SaaS providers and solutions and make a normative and rational decision to reduce organizational risk exposure. Despite its theoretical utility, further qualitative research is needed to determine the viability of the S-CRA framework in an empirical SaaS selection scenario.