132
security and data privacy for cloud service providers and their customers.
Five common approaches for protecting cloud systems and data in extant
literature include multi-cloud storage, homomorphic encryption schemes,
secure sharing systems, deployment of intermediary components, as well
as more traditional security and privacy methods.
Multi-cloud storage strategies seek to reduce security and availability
risks by diversifying this risk through the use of multiple cloud storage
service providers (Bucur et al. 2018). For example, Alqahtani and KouadriMostefaou (2014) propose a framework that ensures the security of mobile
cloud computing by deploying distributed multi-cloud storage, data
encryption, and data compression techniques. The framework operates by
dividing the data into different segments at the user end based on the
preference selected by the user before the encryption and compression of
the segments. The compressed segments are stored on distributed multicloud storage service providers. Similarly, Abdalla and Pathan (2014) presented a framework using a data protection manager (DPM) deployed for
the transmission of data to the cloud service provider. The DPM both
fragments and merges the data in the proposed framework. First, it breaks
the data into fragments and transmits them to the multi-cloud for storage.
When a user requests the data, the DPM merges the data. The service
provider maps the information of fragmented and merged data to the individual users and the multi-cloud technique applied protects data on other
segments if one segment is compromised. While multi-cloud storage in
theory has many advantageous attributes, in practice, it has significant
Table 7.1 (continued)
Implementation
• Risk analysis
• Development practices, including architecture, coding,
documentation, and testing
• Training and education
• Terms of business
• Marketing and sales practices
• Operations practices, including deployment,
maintenance, sales & support, and risk management
• Enforcement of intents and dispute resolution
Evidence
• Self-assessment
• Accreditation by third parties
• External audit
Adapted from Mundie et al. (2002)
O. M. ALOFE AND K. FATEMA
security and data privacy for cloud service providers and their customers.
Five common approaches for protecting cloud systems and data in extant
literature include multi-cloud storage, homomorphic encryption schemes,
secure sharing systems, deployment of intermediary components, as well
as more traditional security and privacy methods.
Multi-cloud storage strategies seek to reduce security and availability
risks by diversifying this risk through the use of multiple cloud storage
service providers (Bucur et al. 2018). For example, Alqahtani and KouadriMostefaou (2014) propose a framework that ensures the security of mobile
cloud computing by deploying distributed multi-cloud storage, data
encryption, and data compression techniques. The framework operates by
dividing the data into different segments at the user end based on the
preference selected by the user before the encryption and compression of
the segments. The compressed segments are stored on distributed multicloud storage service providers. Similarly, Abdalla and Pathan (2014) presented a framework using a data protection manager (DPM) deployed for
the transmission of data to the cloud service provider. The DPM both
fragments and merges the data in the proposed framework. First, it breaks
the data into fragments and transmits them to the multi-cloud for storage.
When a user requests the data, the DPM merges the data. The service
provider maps the information of fragmented and merged data to the individual users and the multi-cloud technique applied protects data on other
segments if one segment is compromised. While multi-cloud storage in
theory has many advantageous attributes, in practice, it has significant
Table 7.1 (continued)
Implementation
• Risk analysis
• Development practices, including architecture, coding,
documentation, and testing
• Training and education
• Terms of business
• Marketing and sales practices
• Operations practices, including deployment,
maintenance, sales & support, and risk management
• Enforcement of intents and dispute resolution
Evidence
• Self-assessment
• Accreditation by third parties
• External audit
Adapted from Mundie et al. (2002)
O. M. ALOFE AND K. FATEMA
