131
Table 7.1 Definition of goals, means, and execution in trustworthy computing
Goals
The basis for a customer’s decision to trust a system
Security & privacy
The expectation of attack-resilient systems and that the
confidentiality, integrity, and availability of the system and its
data are protected.
The customer can control data about themselves, and those
using such data adhere to fair information principles
Reliability
The customer can depend on the product to fulfil its
functions when required to do so.
Business integrity
The vendor of a product behaves in a responsive and
responsible manner.
Means
The business and engineering considerations that enable
a system supplier to deliver on the Goals
Secure by design, secure
by default, secure in
deployment
A process is in place to protect the confidentiality, integrity,
and availability of data and systems at every phase of the
software development process.
Fair information principles The collection and sharing of end-user data requires the
consent of the end user, and privacy is respected, and data is
only used in line with Fair Information Practices.
Availability
The system is available for use as required.
Manageability
The system is easy to install and manage, relative to its size
and complexity.
Accuracy
The system performs its functions correctly. Data is
protected from corruption and loss.
Usability
The software is easy to use and suitable to the user’s needs.
Responsiveness
The vendor accepts responsibility for problems, and takes
action to correct them. Support is available to customers as
needed throughout their engagement with vendor.
Transparency
The vendor is open in its dealings with customers. Its
motives are clear, it keeps its word, and customers know
where they stand in a transaction or interaction with the
vendor.
Execution
The way an organisation conducts its operations to
deliver the components required for trustworthy
computing
Intents
• Company policies, directives, benchmarks, and
guidelines
• Contracts and undertakings with customers, including
Service Level Agreements (SLAs)
• Corporate, industry and regulatory standards
Government legislation, policies, and regulations
(continued)
7 TRUSTWORTHY CLOUD COMPUTING
Table 7.1 Definition of goals, means, and execution in trustworthy computing
Goals
The basis for a customer’s decision to trust a system
Security & privacy
The expectation of attack-resilient systems and that the
confidentiality, integrity, and availability of the system and its
data are protected.
The customer can control data about themselves, and those
using such data adhere to fair information principles
Reliability
The customer can depend on the product to fulfil its
functions when required to do so.
Business integrity
The vendor of a product behaves in a responsive and
responsible manner.
Means
The business and engineering considerations that enable
a system supplier to deliver on the Goals
Secure by design, secure
by default, secure in
deployment
A process is in place to protect the confidentiality, integrity,
and availability of data and systems at every phase of the
software development process.
Fair information principles The collection and sharing of end-user data requires the
consent of the end user, and privacy is respected, and data is
only used in line with Fair Information Practices.
Availability
The system is available for use as required.
Manageability
The system is easy to install and manage, relative to its size
and complexity.
Accuracy
The system performs its functions correctly. Data is
protected from corruption and loss.
Usability
The software is easy to use and suitable to the user’s needs.
Responsiveness
The vendor accepts responsibility for problems, and takes
action to correct them. Support is available to customers as
needed throughout their engagement with vendor.
Transparency
The vendor is open in its dealings with customers. Its
motives are clear, it keeps its word, and customers know
where they stand in a transaction or interaction with the
vendor.
Execution
The way an organisation conducts its operations to
deliver the components required for trustworthy
computing
Intents
• Company policies, directives, benchmarks, and
guidelines
• Contracts and undertakings with customers, including
Service Level Agreements (SLAs)
• Corporate, industry and regulatory standards
Government legislation, policies, and regulations
(continued)
7 TRUSTWORTHY CLOUD COMPUTING
