<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/xsl" href="static/style.xsl"?><OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd"><responseDate>2026-09-19T00:27:52Z</responseDate><request verb="GetRecord" identifier="oai:dspace.mit.edu:1721.1/151640" metadataPrefix="dim">https://dspace.mit.edu/server/oai/request</request><GetRecord><record><header><identifier>oai:dspace.mit.edu:1721.1/151640</identifier><datestamp>2023-08-01T03:50:53Z</datestamp><setSpec>com_1721.1_7582</setSpec><setSpec>com_1721.1_7581</setSpec><setSpec>col_1721.1_131023</setSpec></header><metadata><dim:dim xmlns:dim="http://www.dspace.org/xmlns/dspace/dim" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:doc="http://www.lyncode.com/xoai" xsi:schemaLocation="http://www.dspace.org/xmlns/dspace/dim http://www.dspace.org/schema/dim.xsd">
   <dim:field mdschema="dc" element="contributor" qualifier="advisor">Weitzner, Daniel</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="advisor">Reynolds, Taylor</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="author">Lewke, Damien</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="department">System Design and Management Program.</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="accessioned">2023-07-31T19:55:05Z</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="available">2023-07-31T19:55:05Z</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="issued">2023-06</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="submitted">2023-06-23T19:55:06.234Z</dim:field>
   <dim:field mdschema="dc" element="identifier" qualifier="uri">https://hdl.handle.net/1721.1/151640</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="abstract">This paper proposes a novel cloud security benchmarking framework and scoring system to improve cyber risk management. Cyber risk management is challenging and has become even more difficult as organizations digitally transform their business and IT from on-premises environments to cloud infrastructure. Threats proliferate as organizations’ attack surfaces expand due to shadow IT, software supply chain security, outsourced networking, and virtualization. Existing cyber risk management frameworks and controls are too exhaustive or generic and provide no means for organizations to assess their cyber risk against their peers. The MIT-IBM CloudSec 16 developed in this paper is a new security benchmarking framework and scoring system built specifically for cloud deployments in the financial service sector. When paired with MIT’s SCRAM secure computation platform, the MIT-IBM CloudSec 16 can provide an overview of cloud security in the financial service sector and enable organizations to and remediate areas of relative weakness.</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="degree">S.M.</dim:field>
   <dim:field mdschema="dc" element="publisher">Massachusetts Institute of Technology</dim:field>
   <dim:field mdschema="dc" element="rights">In Copyright - Educational Use Permitted</dim:field>
   <dim:field mdschema="dc" element="rights">Copyright retained by author(s)</dim:field>
   <dim:field mdschema="dc" element="rights" qualifier="uri">https://rightsstatements.org/page/InC-EDU/1.0/</dim:field>
   <dim:field mdschema="dc" element="title">The MIT-IBM CloudSec 16: A Cloud Cybersecurity Benchmarking Framework</dim:field>
   <dim:field mdschema="dc" element="type">Thesis</dim:field>
   <dim:field mdschema="dc" element="format" qualifier="mimetype">application/pdf</dim:field>
   <dim:field mdschema="mit" element="thesis" qualifier="degree">Master</dim:field>
   <dim:field mdschema="thesis" element="degree" qualifier="name">Master of Science in Engineering and Management</dim:field>
   <dim:field mdschema="dspace" element="entity" qualifier="type">Publication</dim:field>
   <dim:field mdschema="others" element="access-status">unknown</dim:field>
   <dim:field mdschema="others" element="access-status">unknown</dim:field>
   <dim:field mdschema="cerif" element="openaire" authority="" confidence="-1">&lt;Publication xmlns="https://www.openaire.eu/cerif-profile/1.1/" id="6f3d3cf9-1492-4c00-afff-84f0fa679e0b">
	&lt;Type xmlns="https://www.openaire.eu/cerif-profile/vocab/COAR_Publication_Types">http://purl.org/coar/resource_type/c_1843&lt;/Type>
   	&lt;Title>The MIT-IBM CloudSec 16: A Cloud Cybersecurity Benchmarking Framework&lt;/Title>
   	&lt;PublishedIn>
    	&lt;Publication>
      	&lt;/Publication>
   	&lt;/PublishedIn>
   	&lt;PublicationDate>2023-06&lt;/PublicationDate>
   	&lt;Authors>
      	&lt;Author>
        	&lt;DisplayName>Lewke, Damien&lt;/DisplayName>
         	&lt;Affiliation>
         		&lt;OrgUnit>
         		&lt;/OrgUnit>
         	&lt;/Affiliation>
      	&lt;/Author>
	&lt;/Authors>
   	&lt;Editors>
	&lt;/Editors>
    &lt;Publishers>
        &lt;Publisher>
            &lt;DisplayName>Massachusetts Institute of Technology&lt;/DisplayName>
            &lt;OrgUnit />
        &lt;/Publisher>
    &lt;/Publishers>
    &lt;License>https://rightsstatements.org/page/InC-EDU/1.0/&lt;/License>
   	&lt;Abstract>This paper proposes a novel cloud security benchmarking framework and scoring system to improve cyber risk management. Cyber risk management is challenging and has become even more difficult as organizations digitally transform their business and IT from on-premises environments to cloud infrastructure. Threats proliferate as organizations’ attack surfaces expand due to shadow IT, software supply chain security, outsourced networking, and virtualization. Existing cyber risk management frameworks and controls are too exhaustive or generic and provide no means for organizations to assess their cyber risk against their peers. The MIT-IBM CloudSec 16 developed in this paper is a new security benchmarking framework and scoring system built specifically for cloud deployments in the financial service sector. When paired with MIT’s SCRAM secure computation platform, the MIT-IBM CloudSec 16 can provide an overview of cloud security in the financial service sector and enable organizations to and remediate areas of relative weakness.&lt;/Abstract>
	&lt;Access xmlns="http://purl.org/coar/access_right" 
    >
    &lt;/Access>
&lt;/Publication>
</dim:field>
</dim:dim>
</metadata></record></GetRecord></OAI-PMH>