{"id":"https://openalex.org/W7154354262","doi":"https://doi.org/10.1145/3808691","title":"Cloud Outsourcing Risk Management for Cloud Consumers: A Systematic Literature Review","display_name":"Cloud Outsourcing Risk Management for Cloud Consumers: A Systematic Literature Review","publication_year":2026,"publication_date":"2026-04-14","ids":{"openalex":"https://openalex.org/W7154354262","doi":"https://doi.org/10.1145/3808691"},"language":"en","primary_location":{"id":"doi:10.1145/3808691","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3808691","pdf_url":null,"source":{"id":"https://openalex.org/S157921468","display_name":"ACM Computing Surveys","issn_l":"0360-0300","issn":["0360-0300","1557-7341"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Computing Surveys","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://doi.org/10.1145/3808691","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5042915066","display_name":"Muhammad Yasir Muzayan Haq","orcid":"https://orcid.org/0000-0001-6697-6645"},"institutions":[{"id":"https://openalex.org/I94624287","display_name":"University of Twente","ror":"https://ror.org/006hf6230","country_code":"NL","type":"education","lineage":["https://openalex.org/I94624287"]}],"countries":["NL"],"is_corresponding":false,"raw_author_name":"Muhammad Yasir Muzayan Haq","raw_affiliation_strings":["University of Twente"],"raw_orcid":"https://orcid.org/0000-0001-6697-6645","affiliations":[{"raw_affiliation_string":"University of Twente","institution_ids":["https://openalex.org/I94624287"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5126895880","display_name":"Siraj Anand","orcid":null},"institutions":[{"id":"https://openalex.org/I94624287","display_name":"University of Twente","ror":"https://ror.org/006hf6230","country_code":"NL","type":"education","lineage":["https://openalex.org/I94624287"]}],"countries":["NL"],"is_corresponding":false,"raw_author_name":"Siraj Anand","raw_affiliation_strings":["University of Twente"],"raw_orcid":"https://orcid.org/0009-0003-2579-5495","affiliations":[{"raw_affiliation_string":"University of Twente","institution_ids":["https://openalex.org/I94624287"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5051441037","display_name":"L.J.M. Nieuwenhuis","orcid":null},"institutions":[{"id":"https://openalex.org/I94624287","display_name":"University of Twente","ror":"https://ror.org/006hf6230","country_code":"NL","type":"education","lineage":["https://openalex.org/I94624287"]}],"countries":["NL"],"is_corresponding":false,"raw_author_name":"L.J.M. Nieuwenhuis","raw_affiliation_strings":["University of Twente"],"raw_orcid":"https://orcid.org/0000-0002-6438-7756","affiliations":[{"raw_affiliation_string":"University of Twente","institution_ids":["https://openalex.org/I94624287"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5053272015","display_name":"Abhishta Abhishta","orcid":"https://orcid.org/0000-0001-7122-3103"},"institutions":[{"id":"https://openalex.org/I94624287","display_name":"University of Twente","ror":"https://ror.org/006hf6230","country_code":"NL","type":"education","lineage":["https://openalex.org/I94624287"]}],"countries":["NL"],"is_corresponding":false,"raw_author_name":"Abhishta Abhishta","raw_affiliation_strings":["University of Twente"],"raw_orcid":"https://orcid.org/0000-0001-7122-3103","affiliations":[{"raw_affiliation_string":"University of Twente","institution_ids":["https://openalex.org/I94624287"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":{"value":0.60449074,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"58","issue":"12","first_page":"1","last_page":"36"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11614","display_name":"Cloud Data Security Solutions","score":0.38839998841285706,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11614","display_name":"Cloud Data Security Solutions","score":0.38839998841285706,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11912","display_name":"Outsourcing and Supply Chain Management","score":0.319599986076355,"subfield":{"id":"https://openalex.org/subfields/1404","display_name":"Management Information Systems"},"field":{"id":"https://openalex.org/fields/14","display_name":"Business, Management and Accounting"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T13927","display_name":"Cyberloafing and Workplace Behavior","score":0.02539999969303608,"subfield":{"id":"https://openalex.org/subfields/3317","display_name":"Demography"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/cloud-computing","display_name":"Cloud computing","score":0.7699999809265137},{"id":"https://openalex.org/keywords/outsourcing","display_name":"Outsourcing","score":0.6776000261306763},{"id":"https://openalex.org/keywords/vendor","display_name":"Vendor","score":0.6219000220298767},{"id":"https://openalex.org/keywords/systematic-review","display_name":"Systematic review","score":0.5925999879837036},{"id":"https://openalex.org/keywords/risk-management","display_name":"Risk management","score":0.5482000112533569},{"id":"https://openalex.org/keywords/confidentiality","display_name":"Confidentiality","score":0.4708000123500824},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.46560001373291016},{"id":"https://openalex.org/keywords/encryption","display_name":"Encryption","score":0.39570000767707825}],"concepts":[{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.7699999809265137},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6991000175476074},{"id":"https://openalex.org/C46934059","wikidata":"https://www.wikidata.org/wiki/Q61515","display_name":"Outsourcing","level":2,"score":0.6776000261306763},{"id":"https://openalex.org/C2777338717","wikidata":"https://www.wikidata.org/wiki/Q1762621","display_name":"Vendor","level":2,"score":0.6219000220298767},{"id":"https://openalex.org/C189708586","wikidata":"https://www.wikidata.org/wiki/Q1504425","display_name":"Systematic review","level":3,"score":0.5925999879837036},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.57669997215271},{"id":"https://openalex.org/C32896092","wikidata":"https://www.wikidata.org/wiki/Q189447","display_name":"Risk management","level":2,"score":0.5482000112533569},{"id":"https://openalex.org/C71745522","wikidata":"https://www.wikidata.org/wiki/Q2476929","display_name":"Confidentiality","level":2,"score":0.4708000123500824},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.46560001373291016},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.43639999628067017},{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.39570000767707825},{"id":"https://openalex.org/C2778143579","wikidata":"https://www.wikidata.org/wiki/Q831801","display_name":"Business continuity","level":2,"score":0.34529998898506165},{"id":"https://openalex.org/C195094911","wikidata":"https://www.wikidata.org/wiki/Q14167904","display_name":"Process management","level":1,"score":0.34360000491142273},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.31929999589920044},{"id":"https://openalex.org/C12174686","wikidata":"https://www.wikidata.org/wiki/Q1058438","display_name":"Risk assessment","level":2,"score":0.31369999051094055},{"id":"https://openalex.org/C9272383","wikidata":"https://www.wikidata.org/wiki/Q5001930","display_name":"Business risks","level":2,"score":0.3043000102043152},{"id":"https://openalex.org/C184842701","wikidata":"https://www.wikidata.org/wiki/Q370563","display_name":"Cloud computing security","level":3,"score":0.2896000146865845},{"id":"https://openalex.org/C192209626","wikidata":"https://www.wikidata.org/wiki/Q190909","display_name":"Focus (optics)","level":2,"score":0.2791000008583069},{"id":"https://openalex.org/C56739046","wikidata":"https://www.wikidata.org/wiki/Q192060","display_name":"Knowledge management","level":1,"score":0.27469998598098755},{"id":"https://openalex.org/C2775924081","wikidata":"https://www.wikidata.org/wiki/Q55608371","display_name":"Control (management)","level":2,"score":0.2558000087738037},{"id":"https://openalex.org/C83163435","wikidata":"https://www.wikidata.org/wiki/Q3954104","display_name":"Security management","level":2,"score":0.2542000114917755},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.25200000405311584},{"id":"https://openalex.org/C2781083858","wikidata":"https://www.wikidata.org/wiki/Q17327049","display_name":"Scientific literature","level":2,"score":0.2517000138759613}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1145/3808691","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3808691","pdf_url":null,"source":{"id":"https://openalex.org/S157921468","display_name":"ACM Computing Surveys","issn_l":"0360-0300","issn":["0360-0300","1557-7341"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Computing Surveys","raw_type":"journal-article"},{"id":"pmh:oai:ris.utwente.nl:publications/d9623f3e-8c09-4e18-9c3c-11a02c23140b","is_oa":true,"landing_page_url":"https://research.utwente.nl/en/publications/d9623f3e-8c09-4e18-9c3c-11a02c23140b","pdf_url":"https://ris.utwente.nl/ws/files/461416661/SLR_Cloud_Risk_Management_7feb2024_submitted_csur.pdf","source":{"id":"https://openalex.org/S4406922991","display_name":"University of Twente Research Information","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Haq, M Y M, Anand, S, Nieuwenhuis, L J M & Abhishta, A 2026, 'Cloud Outsourcing Risk Management for Cloud Consumers : A Systematic Literature Review', ACM computing surveys, vol. 58, no. 12, 297, pp. 1-36. https://doi.org/10.1145/3808691","raw_type":"info:eu-repo/semantics/publishedVersion"}],"best_oa_location":{"id":"doi:10.1145/3808691","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3808691","pdf_url":null,"source":{"id":"https://openalex.org/S157921468","display_name":"ACM Computing Surveys","issn_l":"0360-0300","issn":["0360-0300","1557-7341"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Computing Surveys","raw_type":"journal-article"},"sustainable_development_goals":[{"display_name":"Industry, innovation and infrastructure","id":"https://metadata.un.org/sdg/9","score":0.6354371309280396}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":91,"referenced_works":["https://openalex.org/W333171783","https://openalex.org/W1483077715","https://openalex.org/W1485833866","https://openalex.org/W1993705641","https://openalex.org/W2003229135","https://openalex.org/W2009128540","https://openalex.org/W2021862793","https://openalex.org/W2022140071","https://openalex.org/W2030367271","https://openalex.org/W2032860265","https://openalex.org/W2040295146","https://openalex.org/W2056075452","https://openalex.org/W2060543984","https://openalex.org/W2075191163","https://openalex.org/W2076628994","https://openalex.org/W2089683573","https://openalex.org/W2108375742","https://openalex.org/W2110770770","https://openalex.org/W2116417488","https://openalex.org/W2124493593","https://openalex.org/W2138893874","https://openalex.org/W2141420453","https://openalex.org/W2154107289","https://openalex.org/W2164777277","https://openalex.org/W2183260167","https://openalex.org/W2195720612","https://openalex.org/W2209768828","https://openalex.org/W2275530856","https://openalex.org/W2317218987","https://openalex.org/W2318224047","https://openalex.org/W2319799779","https://openalex.org/W2335832707","https://openalex.org/W2341749628","https://openalex.org/W2431517476","https://openalex.org/W2465500503","https://openalex.org/W2489667510","https://openalex.org/W2520811994","https://openalex.org/W2531689081","https://openalex.org/W2537725778","https://openalex.org/W2602507176","https://openalex.org/W2604994022","https://openalex.org/W2616229336","https://openalex.org/W2616592626","https://openalex.org/W2733064618","https://openalex.org/W2768883253","https://openalex.org/W2788925579","https://openalex.org/W2789258854","https://openalex.org/W2789622866","https://openalex.org/W2801624537","https://openalex.org/W2805257446","https://openalex.org/W2895349620","https://openalex.org/W2895410484","https://openalex.org/W2899822557","https://openalex.org/W2916437501","https://openalex.org/W2938295127","https://openalex.org/W2939184879","https://openalex.org/W2943715367","https://openalex.org/W2945132367","https://openalex.org/W2946986707","https://openalex.org/W3011462710","https://openalex.org/W3029176236","https://openalex.org/W3029387962","https://openalex.org/W3030241699","https://openalex.org/W3040244018","https://openalex.org/W3042047914","https://openalex.org/W3042229692","https://openalex.org/W3043308527","https://openalex.org/W3046095146","https://openalex.org/W3092975800","https://openalex.org/W3094207509","https://openalex.org/W3135360585","https://openalex.org/W3152941878","https://openalex.org/W3162197280","https://openalex.org/W3208431170","https://openalex.org/W4205191869","https://openalex.org/W4236492429","https://openalex.org/W4238477186","https://openalex.org/W4281621168","https://openalex.org/W4285815058","https://openalex.org/W4288057795","https://openalex.org/W4293247992","https://openalex.org/W4311958277","https://openalex.org/W4385412490","https://openalex.org/W4392806465","https://openalex.org/W4393184585","https://openalex.org/W4401830843","https://openalex.org/W4401871255","https://openalex.org/W4406824422","https://openalex.org/W4407204461","https://openalex.org/W4407361218","https://openalex.org/W4416366452"],"related_works":[],"abstract_inverted_index":{"This":[0],"systematic":[1],"literature":[2],"review":[3],"explores":[4],"the":[5,38,49,77,117,136,159,178],"landscape":[6],"of":[7,44,164,193],"risks":[8,61,115,138,157],"and":[9,26,30,59,67,76,90,105,125,139,161,191],"risk":[10,96],"management":[11,97],"techniques":[12,98,184],"in":[13,24,95,116,177],"cloud":[14,22,101,165],"outsourcing,":[15],"with":[16],"a":[17,41,110,174],"focus":[18],"on":[19,113],"assisting":[20],"enterprise":[21],"consumers":[23],"understanding":[25],"mitigating":[27],"both":[28],"technical":[29,104,114,137],"non-technical":[31,106,120],"risks,":[32,121],"despite":[33],"having":[34],"limited":[35],"control":[36],"over":[37],"infrastructures.":[39],"From":[40],"comprehensive":[42],"analysis":[43],"55":[45],"academic":[46],"articles,":[47],"spanning":[48],"period":[50],"from":[51,65,142],"January":[52],"2013":[53],"to":[54,132,158,182],"September":[55],"2022,":[56],"we":[57,87],"identify":[58],"characterize":[60,91],"using":[62],"established":[63],"frameworks":[64],"ENISA":[66],"Cebula":[68],"et":[69,82],"al.":[70,83],"[":[71,84],"20":[72],"].":[73],"Using":[74],"ISO31000":[75],"classification":[78],"proposed":[79],"by":[80],"Ardagna":[81],"4":[85],"],":[86],"also":[88,154,168],"summarize":[89],"23":[92],"main":[93],"strategies":[94],"feasible":[99],"for":[100],"consumers,":[102],"including":[103,122],"measures.":[107],"We":[108,167],"observe":[109,169],"significant":[111],"emphasis":[112],"literature,":[118],"while":[119],"legal,":[123],"organizational,":[124],"policy":[126],"aspects,":[127],"are":[128],"relatively":[129],"underrepresented.":[130],"Threats":[131],"data":[133],"confidentiality":[134],"dominate":[135],"mostly":[140],"originate":[141],"shared":[143],"infrastructure":[144],"issues.":[145],"In":[146],"addition,":[147],"non\u2011technical":[148],"issues":[149],"such":[150,185],"as":[151,186],"vendor":[152],"lock\u2011in":[153],"pose":[155],"catastrophic":[156],"continuity":[160],"business":[162],"operations":[163],"consumers.":[166],"that":[170],"encryption":[171],"still":[172],"plays":[173],"key":[175],"role":[176],"existing":[179],"techniques,":[180],"next":[181],"other":[183],"auditing,":[187],"risk-aware":[188],"software":[189],"development,":[190],"assessments":[192],"third":[194],"parties.":[195]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-04-15T00:00:00"}
