94
practices are often centred on compliance with laws and industry standards. These organizations report little more than privacy metrics mandated by privacy. They may undertake lobbying towards privacy but only
where beneficial to the organization. They have no real philanthropic perspective with regard to privacy. Compliers tend to provide rudimentary
transactional services (for instance Cloudways and Digital Ocean). They
will typically offer security and privacy features at an additional cost, or like
Amazon AWS, allow the CSC to reconfigure private buckets to be nonprivate. Risk-Managers rarely exceed legislative minimums.
In 2019, Capital One (using AWS as their CSP) suffered a breach
impacting 100 m customers’ financial data including social security numbers (Business Insider 2019). The AWS server used by Capital One was
vulnerable to a well-known attack (called server-side request forgery
[SSRF]). AWS denied liability (as their contracts indemnified them) however—without being legally required to do so, AWS’s largest competitors
(Google and Microsoft) had already addressed the threat of SSRF attacks
two years previously.
2
5.4.1.2 Integrators
Integrator CSPs offer robust compliance to privacy legislation whilst integrating society’s increasing expectations to address privacy as a social
responsibility. CSPs in this privacy orientation demonstrate privacy behaviors that measure low on justice and high on control. Relinquishing control (by offering increased justice behaviors) to their CSCs is not important
to these organizations, as they require widespread access to data and systems in order to minimize costs and maximize profit. CSPs in this orientation may actively reflect on ways they can use social issues such as privacy
to gain competitive advantage. For instance, privacy rights for employees,
their families, and local communities may be supported. The CSPs objective in this orientation is to mitigate the erosion of economic value in the
medium term and to achieve longer-term gains by integrating responsible
privacy practices into their daily operations (Zadek 2004). These CSPs not
only want to monetize their cloud service, but they also want to maximize
data value. Although CSPs in this orientation may appear to demonstrate
philanthropic privacy—for example by producing white papers, open
2
https://www.wyden.senate.gov/imo/media/doc/102419%20Wyden%20Warren%20
Letter%20to%20FTC%20RE%20Amazon%20Capital%20One%20Hack.pdf
V. LYONS
Précédent

- 112/166

Suivant