Journal of Embedded Systems, Security and Intelligent Systems
Vol 6, No 3 (2025): September 2025

Cloud Governance Frameworks: CIA-Based Security and Compliance

Rahmika, Afiyah Rifkha (Unknown)
Muhammad Akbar (Unknown)
Deni Luvi Jayanto (Unknown)
Joshua Reska Bu'tu (Unknown)



Article Info

Publish Date
20 Sep 2025

Abstract

Digital transformation has driven organizations to adopt cloud computing as a flexible and efficient IT infrastructure solution. However, differences between public and private cloud models create challenges in maintaining information security and compliance. This study employs a descriptive–comparative approach through an extensive literature review of journals, conference papers, and standards such as ISO/IEC 27001 and the NIST Cybersecurity Framework (CSF). Findings show that public clouds, while offering cost efficiency and scalability, are more vulnerable to external threats due to limited control and multi-tenancy, whereas private clouds provide stronger governance and customization but demand higher internal resources. The hybrid model emerges as a strategic alternative balancing flexibility and control. Integrating the Confidentiality, Integrity, and Availability (CIA) framework enables a structured evaluation of security risks and governance mechanisms across cloud models. The study highlights that effective governance depends on risk-based policies, compliance alignment, and adaptive controls. It concludes that combining ISO/IEC 27001’s prescriptive management system with NIST CSF’s flexible structure can optimize resilience, compliance, and operational sustainability. This integrated governance approach ensures that cloud security aligns with organizational goals and regulatory requirements while addressing evolving digital risks

Copyrights © 2025






Journal Info

Abbrev

JESSI

Publisher

Subject

Computer Science & IT

Description

The Journal of Embedded System Security and Intelligent System (JESSI), ISSN/e-ISSN 2745-925X/2722-273X covers all topics of technology in the field of embedded system, computer and network security, and intelligence system as well as innovative and productive ideas related to emerging technology ...