
Cloud computing is currently a prominent component in implementing digital transformation due to its advantages in scalability, flexibility, and costs reduction. Many governments have formulated systematic cloud migration strategies due to the imperative of developing e-services and the rapid increase in data volume. However, security concerns remain a significant obstacle to the widespread adoption of government clouds and the full utilization of their benefits. This research discusses the security risks associated with adopting government clouds and seeks to develop an integrated security framework based on best practices and global Cybersecurity standards. The aim is to mitigate these risks and enhance the security of cloud computing networks in government institutions by studying the case of cloud adoption in the Syrian public sector, analyzing its requirements, and ultimately defining the foundations of the proposed security framework. This research describes the Syrian government cloud, and classifies the most significant security risks and the solutions implemented within the study environment. This classification depends on the results of a survey and expert interviews. The research then identifies the essential requirements for building a security framework, based on the case study. Furthermore, by integrating the security requirements of the Syrian government cloud with the principles of famous cloud security frameworks, we developed a proposed framework consisting of three levels based on NIST, ISO 27001, and CIS standards. The proposed framework employs a continuous improvement methodology to ensure dynamism and applicability within government institutions. A subsequent study will detail its phases and practical implementation mechanisms.
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 0 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
