International Peer-Reviewed Journal•Open Access•ISSN 2456-8880
irejournals@gmail.com•+91-7433024337

Home / Current Issue / Paper 1710217

1710217 Vol 2 · Issue 8 Download Paper

Cloud Security Baseline Development Using OWASP, CIS Benchmarks, and ISO 27001 for Regulatory Compliance.

Iboro Akpan Essien Emmanuel Cadet Joshua Oluwagbenga Ajayi Eseoghene Daniel Erigha Ehimah Obuse

Subject area: Science,Engineering and Technology  ·  Area of research: Computer Science

Abstract

The increasing adoption of cloud computing across industries has heightened the need for robust, standardized security frameworks that align with regulatory requirements and best practices. This paper presents a comprehensive approach to developing a cloud security baseline by integrating the Open Web Application Security Project (OWASP) guidelines, Center for Internet Security (CIS) Benchmarks, and ISO 27001 standards. These frameworks collectively address application-layer vulnerabilities, system configuration hardening, and holistic information security management, enabling organizations to establish consistent and scalable security postures. By mapping control objectives and security measures across these standards, the proposed baseline ensures that critical assets are safeguarded against evolving cyber threats while maintaining compliance with diverse regulatory regimes. Emphasis is placed on harmonizing security controls to eliminate redundancy, improve operational efficiency, and facilitate easier audits. The integration of OWASP mitigates application-specific risks, CIS Benchmarks strengthens platform and service configurations, and ISO 27001 provides governance, risk management, and continuous improvement structures. The study underscores the importance of adopting a unified security baseline not only as a technical safeguard but also as a strategic enabler of trust, regulatory alignment, and operational resilience in multi-cloud and hybrid environments. This framework offers a practical pathway for enterprises to meet both security and compliance obligations in today?s complex digital landscape.

Keywords

Cloud Security, OWASP, CIS Benchmarks, ISO 27001, Regulatory Compliance

References

[1] Abayomi, A. A., Eze, B. U., & Okonkwo, C. J. (2019). Harmonizing industry standards for enhanced regulatory compliance in multi-cloud systems. IRE Journals, 4(2), 118–126.

[2] Adebayo, S. O., Oladimeji, T. E., & Yusuf, K. M. (2019). Cross-referencing security frameworks for unified compliance in cloud ecosystems. IRE Journals, 3(12), 92–101.

[3] Adekunle, B. I., Musa, A. I., &Eze, B. U. (2019). Designing scalable security architectures for multi-cloud infrastructures. IRE Journals, 3(11), 97–105.

[4] Adekunle, B. I., Onifade, O. F., &Oladipo, I. A. (2019). Leveraging OWASP guidelines for mitigating application-layer vulnerabilities in cloud ecosystems. IRE Journals, 3(9), 76–84.

[5] Adenuga, T., Ayobami, A.T. & Okolo, F.C., 2019. Laying the Groundwork for Predictive Workforce Planning Through Strategic Data Analytics and Talent Modeling. IRE Journals, 3(3), pp.159–161. ISSN: 2456-8880.

[6] Alharthi, A., Yahya, F., & Walters, R. (2019). An overview of cloud computing security and privacy issues. Journal of Theoretical and Applied Information Technology, 97(1), 1–14.

[7] Bello, R. O., Adewumi, A. O., & Yusuf, K. M. (2019). Control harmonization strategies for efficient compliance in cloud environments. IRE Journals, 3(9), 83–91.

[8] Bello, R. O., Musa, A. M., &Oladimeji, T. E. (2017). Meeting cross-border data protection laws through integrated cloud governance. Journal of Information Security and Applications, 35, 41–49.

[9] Chukwu, P. U., Adeoye, M. B., &Lawal, F. T. (2018). Comparative analysis of control objectives in OWASP, CIS, and ISO 27001 for enterprise cloud security. International Journal of Computer Applications, 180(44), 15–23.

[10] Chukwu, P. U., Ibrahim, H. A., &Adeoye, M. B. (2018). Regulatory compliance frameworks for global data protection in cloud computing. International Journal of Cloud Computing and Services Science, 7(3), 145–153.

[11] Evans-Uzosike, I.O. & Okatta, C.G., 2019. Strategic Human Resource Management: Trends, Theories, and Practical Implications. Iconic Research and Engineering Journals, 3(4), pp.264-270.

[12] Eze, B. U., Abayomi, A. A., & Okonkwo, C. J. (2019). Implementing ISO 27001 for holistic information security governance in cloud environments. IRE Journals, 4(2), 77–85.

[13] Eze, B. U., Musa, A. I., & Okonkwo, C. J. (2019). Establishing unified security baselines for scalable regulatory adherence in hybrid cloud environments. IRE Journals, 3(8), 99–107.

[14] Gonzalez, C., & Jensen, M. (2018). Data protection and compliance challenges in multi-jurisdictional cloud environments. Journal of Cloud Computing: Advances, Systems and Applications, 7(1), 12–26.

[15] Ibitoye, B. A., AbdulWahab, R., & Mustapha, S. D. (2017). Estimation of drivers’ critical gap acceptance and follow-up time at four–legged unsignalized intersection. CARD International Journal of Science and Advanced Innovative Research, 1(1), 98-107.

[16] Ibrahim, H. A., Bello, R. O., &Ogunleye, A. A. (2017). Scalability considerations in integrated cloud security governance. Journal of Cloud Computing: Advances, Systems and Applications, 6(2), 45–54.

[17] Ibrahim, H. A., Musa, A. M., & Bello, R. O. (2017). Framework integration for enhanced governance and compliance in multi-cloud environments. Journal of Information Security and Applications, 35, 27–35.

[18] ISACA and Security Scorecard. (2019). Continuous Oversight in the Cloud: How to Improve Cloud Security, Privacy and Compliance. ISACA.

[19] Lawal, F. T., Chukwu, P. U., & Musa, A. M. (2018). Reducing overlap in multi-framework security implementations. International Journal of Computer Applications, 182(20), 25–33.

[20] Musa, A. I., Adekunle, B. I., &Oladipo, I. A. (2019). Implementing CIS Benchmarks for enhanced cloud infrastructure resilience. IRE Journals, 3(11), 88–96.

[21] Nwaimo, C.S., Oluoha, O.M. & Oyedokun, O., 2019. Big Data Analytics: Technologies, Applications, and Future Prospects. IRE Journals, 2(11), pp.411–419. DOI: 10.46762/IRECEE/2019.51123.

[22] Nwankwo, A. O., Musa, A. I., &Abayomi, A. A. (2019). Evolutionary trends in cloud adoption and the emerging security landscape. IRE Journals, 3(12), 115–123.

[23] Nwankwo, A. O., Onifade, O. F., &Adewoye, M. B. (2019). Benchmark-driven security optimization for cross-platform cloud deployments. IRE Journals, 4(4), 93–101.

[24] Ogunleye, A. A., Ibrahim, H. A., &Adeoye, M. B. (2017). Streamlining security and compliance through integrated control mapping. Journal of Information Security and Applications, 34, 19–26.

[25] Okonkwo, C. J., Abayomi, A. A., & Musa, A. I. (2019). Enhancing cloud application resilience through OWASP-driven security controls. IRE Journals, 4(2), 98–106.

[26] Oladimeji, T. E., Lawal, F. T., &Chukwu, P. U. (2018). Adaptive security frameworks for hybrid cloud scalability. International Journal of Cloud Computing and Services Science, 7(4), 211–219.

[27] Oladipo, I. A., Nwankwo, A. O., & Musa, A. I. (2019). Establishing unified compliance strategies through integrated security frameworks in cloud environments. IRE Journals, 3(10), 91–99.

[28] Oladipo, I. A., Nwankwo, A. O., &Adekunle, B. I. (2019). ISO 27001-driven strategies for continuous information security improvement. IRE Journals, 4(3), 89–97.

[29] Onifade, O. F., Musa, A. I., &Adewoye, M. B. (2019). Aligning ISO 27001 controls with multi-cloud compliance requirements. IRE Journals, 3(10), 105–113.

[30] Oyedokun, O.O., 2019.Green Human Resource Management Practices (GHRM) and Its Effect on Sustainable Competitive Edge in the Nigerian Manufacturing Industry: A Study of Dangote Nigeria Plc. MBA Dissertation, Dublin Business School.

[31] Pearson, S., &Charlesworth, A. (2017). Accountability as a way forward for privacy protection in the cloud. IEEE Security & Privacy, 15(5), 68–77.

[32] Sharma, A., Adekunle, B.I., Ogeawuchi, J.C., Abayomi, A.A. & Onifade, O. (2019) 'IoT-enabled Predictive Maintenance for Mechanical Systems: Innovations in Real-time Monitoring and Operational Excellence', IRE Journals, 2(12), pp. 1-10.

How to cite this paper

Iboro Akpan Essien, Emmanuel Cadet, Joshua Oluwagbenga Ajayi, Eseoghene Daniel Erigha, Ehimah Obuse "Cloud Security Baseline Development Using OWASP, CIS Benchmarks, and ISO 27001 for Regulatory Compliance." Iconic Research And Engineering Journals Volume 2 Issue 8 2019 Page 250-260
Iboro Akpan Essien, Emmanuel Cadet, Joshua Oluwagbenga Ajayi, Eseoghene Daniel Erigha, Ehimah Obuse "Cloud Security Baseline Development Using OWASP, CIS Benchmarks, and ISO 27001 for Regulatory Compliance." Iconic Research And Engineering Journals, vol. 2, no. 8, Feb. 2019
Iboro Akpan Essien, Emmanuel Cadet, Joshua Oluwagbenga Ajayi, Eseoghene Daniel Erigha, Ehimah Obuse (2019). Cloud Security Baseline Development Using OWASP, CIS Benchmarks, and ISO 27001 for Regulatory Compliance.. Iconic Research And Engineering Journals, 2(8).
Iboro Akpan Essien, Emmanuel Cadet, Joshua Oluwagbenga Ajayi, Eseoghene Daniel Erigha, Ehimah Obuse "Cloud Security Baseline Development Using OWASP, CIS Benchmarks, and ISO 27001 for Regulatory Compliance." Iconic Research And Engineering Journals, vol. 2, no. 8, Feb. 2019.
@article{1710217,
      author = {Iboro Akpan Essien, Emmanuel Cadet, Joshua Oluwagbenga Ajayi, Eseoghene Daniel Erigha, Ehimah Obuse},
      title = {Cloud Security Baseline Development Using OWASP, CIS Benchmarks, and ISO 27001 for Regulatory Compliance.},
      journal = {Iconic Research And Engineering Journals},
      year = {2019},
      volume = {2},
      number = {8},
      pages = {250-260},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1710217.pdf},
      abstract = {The increasing adoption of cloud computing across industries has heightened the need for robust, standardized security frameworks that align with regulatory requirements and best practices. This paper presents a comprehensive approach to developing a cloud security baseline by integrating the Open Web Application Security Project (OWASP) guidelines, Center for Internet Security (CIS) Benchmarks, and ISO 27001 standards. These frameworks collectively address application-layer vulnerabilities, system configuration hardening, and holistic information security management, enabling organizations to establish consistent and scalable security postures. By mapping control objectives and security measures across these standards, the proposed baseline ensures that critical assets are safeguarded against evolving cyber threats while maintaining compliance with diverse regulatory regimes. Emphasis is placed on harmonizing security controls to eliminate redundancy, improve operational efficiency, and facilitate easier audits. The integration of OWASP mitigates application-specific risks, CIS Benchmarks strengthens platform and service configurations, and ISO 27001 provides governance, risk management, and continuous improvement structures. The study underscores the importance of adopting a unified security baseline not only as a technical safeguard but also as a strategic enabler of trust, regulatory alignment, and operational resilience in multi-cloud and hybrid environments. This framework offers a practical pathway for enterprises to meet both security and compliance obligations in today?s complex digital landscape.},
      keywords = {Cloud Security, OWASP, CIS Benchmarks, ISO 27001, Regulatory Compliance},
      month = {February},
  }