This content is only partially available in English.

Motivation and Relevance

According to the Cloud Monitor 2021 study by the German Association for Information Technology, Telecommunications, and New Media (bitkom e.V.), 82% of companies in Germany with 20 or more employees rely on cloud computing [He21]. In 2019, that figure was 76% of companies [He21]. Cloud computing enables organizations to procure resources (networks, servers, storage, applications, and services) on an as-needed basis via high-speed networks with minimal management effort. However, threats to information security stand in the way of widespread acceptance and adoption of cloud computing. To prevent information security breaches in cloud computing, organizations can implement specific measures and align themselves with relevant standards. For example, the international standard ISO/IEC 27001:2013 describes security techniques and requirements for an information security management system (ISMS), whose primary objective is to protect information security in terms of the three protection objectives of confidentiality, integrity, and availability, while taking opportunities and risks into account. The ISO/IEC 27001:2013 standard describes secure software development in Annex A, Section 14.2, “Security in Development and Support Processes.” A secure software development process is becoming increasingly important for reducing vulnerabilities and integrates security practices into all phases of a software development project [Do19; Wa13].

Problem Statement

The problem is that the use of cloud computing for the storage and processing of critical business data by organizations in Germany is hampered by information security concerns, thereby preventing or limiting organizations in Germany from accessing the following benefits and opportunities of cloud computing [Be13]: cost savings, high scalability, availability, elasticity, and flexibility, energy efficiency and environmental protection, location independence, simplicity, independence from proprietary operating systems, security, reduction of data sets and processing operations through centralization, promotion of innovation, and future-proofing. This problem can be countered through a secure software development process, assuming that secure software development will also result in cloud applications with a higher level of security. When implementing secure software development, there are influencing factors from both a strategic and an operational perspective. Secure software development affects systems, processes, and tools in equal measure. Processes and tools that are interrelated can be described as a system according to Bertalanffy’s general systems theory [Be49] [Be49;Fu72]. This doctoral project focuses on the consideration of systems, processes, and tools.

State of the Art

The existing literature primarily seeks to determine why companies fail to establish secure software development processes—or establish only inadequate ones—rather than optimizing their success: Geer [Ge10] notes that the majority of surveyed companies perceive a secure software development process as too time-consuming or are unaware of secure software development. Alghamdi [Al20] investigated which characteristics have a positive influence on the secure software development process. Assal and Chiasson [As18] identified discrepancies between the conceptual description of secure software development and the practices actually followed in organizations. When implementing a secure software development process for cloud applications, organizations face the question of which factors have a positive influence on success, where success is defined as an increased level of security for cloud applications. Research on success factors is based on the assumption that, despite the multidimensional nature of success and the multicausal nature of potential success factors, a few key success factors can be identified that significantly influence success [Ba09; Da94]. It can be divided into the functions of selection, explication, and technology [Da94]. During the selection phase, potential success factors that may be related to success are chosen from a multitude of factors. These potential success factors are then evaluated against success indicators during the explication phase. Technology represents the set of tools that enables the reduction of complexity and the structuring of success factors [Ba09; Da94]. Research into success factors in secure software development for cloud applications plays a crucial role for organizations in Germany, as its findings highlight the factors influencing success, enabling organizations to design their own secure software development processes, thereby increasing the effectiveness and efficiency of their secure software development and, as a result, producing cloud applications with a higher level of security.

Objective of the Doctoral Project

The objective of this doctoral dissertation is to identify and validate success factors in the secure software development of cloud applications from strategic and operational perspectives, with particular emphasis on systems, processes, and tools, in order to increase the security level of cloud applications. The intended outcome is a model of success factors in secure software development for cloud applications. When appropriately applied, the identified and validated success factors are expected to have a positive effect on the use of cloud computing for the storage and processing of critical business data by organizations in Germany.

Research Questions and Approach

This doctoral dissertation aims to contribute to answering the following research questions (RQs), which are justified below:
1. What characteristics define a cloud application?
2. How can the success of secure software development for cloud applications be measured?
3. What role do strategic and operational aspects play in the secure software development of cloud applications?
4. What roles do systems, processes, and tools play in the secure software development of cloud applications?
5. What theoretical foundations explain success in secure software development for cloud applications from a strategic and operational perspective?
6. What subjectively validated success factors exist in secure software development for cloud applications from a strategic and operational perspective?
7. What objectively validated success factors exist in the secure software development of cloud applications from an operational perspective and, where applicable, a strategic perspective?
To begin with, the concept of a cloud application and its characteristics must be systematized from the perspective of German organizations (see FF1). In addition, a metric for success must be developed. One possible metric is the Common Vulnerability Scoring System (CVSS) (see FF2). A key focus of the doctoral project is on considering both the strategic and operational perspectives (see FF3) as well as the systems, tools, and processes (see FF4). Identifying suitable theories is necessary to enable a theory-driven approach (see FF5). The first and second sub-studies will survey experts and survey participants regarding their subjective perceptions (see FF6). The results will be further examined through a field experiment (see FF7). The doctoral project is structured into three sub-studies: Sub-study I is a qualitative-exploratory expert study that identifies potential success factors using both inductive and deductive methods (based on a preliminary model). Substudy II quantitatively tests the expanded model using theory-driven hypotheses. Substudy III validates individual subjectively validated success factors in a field experiment.

Substudies

The approach of the doctoral project is divided into three substudies:

  • Substudy I is a qualitative-exploratory expert study that identifies potential success factors inductively and deductively (based on a preliminary model).
  • Substudy II quantitatively tests the expanded model using theory-driven hypotheses.
  • Substudy III validates individual subjectively validated success factors in a field experiment.

The sub-studies are intended to contribute to answering the following research questions (RQs), which are justified below:

  1. What characteristics define a cloud application?
  2. How can the success of secure software development for cloud applications be measured?
  3. What role do strategic and operational aspects play in the secure software development of cloud applications?
  4. What roles do systems, processes, and tools play in the secure software development of cloud applications?
  5. What theoretical foundations explain success in the secure software development of cloud applications from a strategic and operational perspective?
  6. What subjectively validated success factors exist in the secure software development of cloud applications from a strategic and operational perspective?
  7. What objectively validated success factors exist in the secure software development of cloud applications from an operational perspective and, where applicable, a strategic perspective?

First, the concept of cloud applications and their characteristics must be systematized from the perspective of German organizations (see FF1). In addition, a metric for success must be developed. One possible metric is the Common Vulnerability Scoring System (CVSS) (see FF2). A key focus of the doctoral project is on considering the strategic and operational perspectives (see FF3) as well as the systems, tools, and processes (see FF4). Identifying suitable theories is necessary to enable a theory-driven approach (see FF5). The first and second sub-studies will survey experts and survey participants regarding their subjective perceptions (see FF6). The results will be further examined through a field experiment (see FF7).

Bibliography

[Al20] Alghamdi, F.: Motivational Company’s Characteristics to Secure Software. pp. 1–5 in 2020 3rd International Conference on Computer Applications & Information Security (ICCAIS). Riyadh, Saudi Arabia: IEEE, 2020.
[As18] Assal, H.; Chiasson, S.: Security in the Software Development Lifecycle. pp. 281–96 in Fourteenth Symposium on Usable Privacy and Security, 2018.
[Ba09] Baumgarth, C.; Eisend, M.; Evanschitzky, H.: Empirical Master Techniques. pp. 3–26 in Empirical Master Techniques, Gabler Verlag, 2009.
[Be13] Bedner, M.: Cloud Computing: Technology, Security, and Legal Framework. Kassel. Kassel University Press, 2013.
[Be49] Bertalanffy, L.: Toward a General Theory of Systems. *Biologia Generalis* 19:114–29, 1949.
[Da94] Daschmann, H. A.: Success Factors/Success Factors of Small and Medium-Sized Enterprises: A Contribution to Research on Success Factors. Stuttgart, 1994.
[Fu72] Fuchs, H.: Systems Theory. pp. 47–57 in *Organization as a System*, edited by K. Bleicher. Wiesbaden: Gabler Verlag, 1972.
[Ge10] Geer, D.: Are Companies Actually Using Secure Development Life Cycles? Computer 43(6):12–16. doi: 10.1109/MC.2010.159., 2010.
[He21] Heidkamp, P.; Vogel, M.; Gentemann, L.: Bitkom Cloud Monitor 2021, 2021.
[Is17] ISO/IEC/IEEE: ISO/IEC/IEEE Systems and Software Engineering Vocabulary. ISO/IEC/IEEE 24765:2017(E) 1–541. doi: 10.1109/IEEESTD.2017.8016712, 2017.
[Sc06] Schmalen, C.; Kunert, M.; Weindlmaier, H.: Research on Success Factors: Theoretical Foundations, Methodological Approach, and Practical Experience in Projects for the Food Industry, 2006.
[To17] Torkura, K. A.; Sukmana, M. I. H.; Meinel, C.: Integrating Continuous Security Assessments in Microservices and Cloud-Native Applications. pp. 171–80 in Proceedings of the 10th International Conference on Utility and Cloud Computing. Austin, Texas, USA: ACM, 2017.
[Wa13] Waidner, M.: Developing Secure Software Through Security by Design, 2013.