10
poor cooperation and opportunistic behaviour (Das and Teng 1996). As a
by-product of both the on-demand nature of cloud computing and dominance of a relatively small number of hyperscale CSPs, standard form contracts are commonplace. Only the largest customers or those customers a
CSP considers strategic, for example governments, have room to negotiate terms, or to develop a personal relationship with these providers. In
the absence of a personal relationship, cloud computing relies largely on
rule- or calculus-based trust, represented by these agreements. As will be
discussed later in Chap. 2, not only do cloud computing contracts typically favour the service provider but cloud customers can find themselves
locked-in from a technical perspective and dependent on the CSP for business continuity with important implications for trust.
Historically, performance risk has been the primary concern with cloud
computing as evidenced by the focus of industry and scholars on service
levels and SLAs. Clearly, availability and access are critical if one outsources
IT infrastructure to the cloud. This is often further complicated by uncertainty related to the functioning of the cloud services, transparency on
how service levels are calculated and of the underlying cloud systems and
associated system data, and exceptions included in cloud contracts. Again,
given the disparity in dependence and impact in the vendor-customer relationship, the risk of failure is significantly higher on the part of the
customer.
The third risk, compliance and regulatory risk is where a customer fails
to adhere to regulatory standards due to the provider’s errors (Anderson
et al. 2014). Increasingly but not exclusively, the primary barriers to cloud
adoption, by organisations and consumers alike, relate to data, and more
specifically the location, integrity, portability, security and privacy of data
(Lynn et al. 2014; Leimbach et al. 2014; Eurostat 2016). Cloud computing is a largely location-independent technology and is built on a chain of
service provision which is largely opaque to the customer. Data may be
stored, processed, and transported across borders, and/or come in to contact with a wide range of partners, without the knowledge of the customer. Furthermore, CSPs, no matter what size are not immune from
security vulnerabilities. Each service model, deployment model, and architecture, and combination and configuration thereof has its own discrete
set of security issues. For SaaS models alone, Subashini and Kavitha (2011)
identify 14 security elements that need to be considered independently of
the PaaS and IaaS infrastructure upon which these are situated. At and
within each layer, different parties may be responsible and accountable for
T. LYNN ET AL.
Précédent

- 28/166

Suivant