Cloud deployment is widely used in the industry due to its irreplaceable convenience and flexibility. However, it is vital to understand the security risks associated with cloud deployment and the shared responsibility model that determines the responsibilities in cloud deployment. In this work, we present Cloud of Assets and Threats (CATS), a serious game designed for industry practitioners to raise awareness about cloud security and the mitigation strategies in the shared responsibility model. The research follows the design science research paradigm. The game idea of CATS is to build a cloud defense strategy by assigning different defensive cards to various roles. An evaluator algorithm determines the success rate of a defense strategy. CATS is designed and implemented in three design iterations and evaluated through three game trial runs and twelve game events with more than 150 participants from the industry. The first design iteration focuses on the design and validity of game logic. In the second design iteration, a digital platform is implemented. The third design iteration refines the game elements, notably the evaluator algorithm. The evaluation process illustrates that CATS fosters the knowledge of cybersecurity-relevant aspects of cloud deployment and the shared responsibility model. A road map towards implementing CATS in an organization is designed and can be used to implement the results of this thesis in practice. The research was conducted in the Security Lifecycle research group in the Technology department of Siemens AG from 2021 to 2024, in collaboration with the Universität der Bundeswehr München and the ISCTE - Instituto Universitário de Lisboa.
«
Cloud deployment is widely used in the industry due to its irreplaceable convenience and flexibility. However, it is vital to understand the security risks associated with cloud deployment and the shared responsibility model that determines the responsibilities in cloud deployment. In this work, we present Cloud of Assets and Threats (CATS), a serious game designed for industry practitioners to raise awareness about cloud security and the mitigation strategies in the shared responsibility model....
»