112
strength of the cloud correlates with the security strength, or otherwise,
of its weakest actor and a breach or an unauthorised access may effectively
impact all users (Ali et al. 2015).
Data security may be regarded as an ethical issue because of the responsibility of those in charge of data collection, storage and usage towards the
multi-stakeholder environment involved in the cloud environment. The
concept of responsibility has a strong ethical connotation when it needs to
go beyond what is prescribed by existing laws, leaving to the willingness of
individuals and companies the duty to respect the rights of the owners of
the data. Each of the abovementioned ethical theories would agree with
the suggestion that data security concurs to the good of data security concurs to the good of society (when data is not related to illegal or unethical
issues). This is evidenced more widely in the context of regulation, where
various legislative provisions pertaining to data issues in the complex cloud
environment have been readily introduced. This highlights that it is relatively more straightforward in some instances to identify a shared legal
minimum requirement with regard to data security.
Ethical issues related to data security, when data is not collected, stored
and managed by the same entity, are particularly significant. Within the
overall cloud context, data security is effectively outsourced to service providers. Security measures adopted are dependent on the delivery models
e.g. for SaaS models (i.e. Software-as-a-Service), users depend entirely on
service providers to prevent multiple users viewing each other’s data, while
in PaaS models (i.e. Platform-as-a-Service), providers may assign some
security elements to those charged with building applications on top of
the platform (Subashini and Kavitha 2011). Reed et al. (2011) highlight
six areas of focus in relation to the lifecycle data in the cloud, ‘Create’,
‘Store’, ‘Use’, ‘Share’, ‘Archive’ and ‘Destroy’ and assert that data security
measures must be implemented at all stages. The importance of security
measures in relation to ‘data remanence’, the ‘residual physical representation of the data after it has been deleted’ is also detailed (Kumar et  al.
2018, p. 693).
In addition, consumers expect providers to facilitate key data properties: ‘integrity’, ‘confidentiality’, and ‘availability’ (Izang et  al. 2017;
Kumar et  al. 2018; Sun et  al. 2014; Tanenbaum and van Steen 2016;
Zissis and Lekkas 2012). Integrity of data assumes a confidence that the
data has not been manipulated or deleted by unauthorised actors; confidentiality assumes data has not been revealed to unauthorised parties and
availability assumes the data is intact and that users can use or recover it as
B. MURPHY AND M. ROCCHI
Précédent

- 130/166

Suivant