11
the security of different elements. This is particularly pertinent in the context of data protection laws, such as the General Data Protection Regulation
(GDPR), where misuse or mismanagement of data can result in significant
fines and penalties, independent of the loss of reputation, and potential
loss of corporate value associated with data and other security breaches
(Goel and Shawky 2009).
Against this backdrop and in the absence of a personal relationship or
knowledge, prospective customers and users of the cloud are faced with a
relatively stark choice: To stay or go. The former involves assuming the
risk laid out, relying on the contracts provided, and the competence,
benevolence, and integrity of the CSP, while mitigating risks by other
means, if possible or desirable. The alternative is to forego the benefits of
the cloud altogether.
1.5 exIstIng approaches to overcomIng trust
BarrIers to cloud adoptIon
In addition to contracts, a variety of trust-building mechanisms have been
proposed by policymakers, industry, and scholars. These include regulation, standardization, certification, communication, and technological
innovation. For over a decade, the European Commission has sought to
mitigate the impact of the risks outlined above through the activities leading to and from the 2012 European Cloud Strategy (European Commission
2012) and subsequent initiatives including the new European digital strategy, Shaping Europe’s Digital Future (European Commission 2020). In
addition to the GDPR, consumer protection regulations are in place to
protect them from behaviour and contracts prejudicial to their consumer
rights (see Chap. 2). Similarly, there have been numerous efforts to support standards not only for cloud system interoperability and data portability, but also for SLAs (see for example C-SIG-SLA 2014), however
these are not mandatory. More recently, there has been a renewed focus
on certification as a means of assurance.
Assurance involves expert practitioners evaluating an CSP against
agreed criteria to improve the degree of confidence of intended users. In
effect, this involves a cloud service provider redesigning their security and
management processes to meet the requirements of a certification scheme,
and then being audited by an independent third party to assess compliance
periodically (Tecnalia 2016). This approach provides an opportunity for
1 UNDERSTANDING TRUST AND CLOUD COMPUTING: AN INTEGRATED…
the security of different elements. This is particularly pertinent in the context of data protection laws, such as the General Data Protection Regulation
(GDPR), where misuse or mismanagement of data can result in significant
fines and penalties, independent of the loss of reputation, and potential
loss of corporate value associated with data and other security breaches
(Goel and Shawky 2009).
Against this backdrop and in the absence of a personal relationship or
knowledge, prospective customers and users of the cloud are faced with a
relatively stark choice: To stay or go. The former involves assuming the
risk laid out, relying on the contracts provided, and the competence,
benevolence, and integrity of the CSP, while mitigating risks by other
means, if possible or desirable. The alternative is to forego the benefits of
the cloud altogether.
1.5 exIstIng approaches to overcomIng trust
BarrIers to cloud adoptIon
In addition to contracts, a variety of trust-building mechanisms have been
proposed by policymakers, industry, and scholars. These include regulation, standardization, certification, communication, and technological
innovation. For over a decade, the European Commission has sought to
mitigate the impact of the risks outlined above through the activities leading to and from the 2012 European Cloud Strategy (European Commission
2012) and subsequent initiatives including the new European digital strategy, Shaping Europe’s Digital Future (European Commission 2020). In
addition to the GDPR, consumer protection regulations are in place to
protect them from behaviour and contracts prejudicial to their consumer
rights (see Chap. 2). Similarly, there have been numerous efforts to support standards not only for cloud system interoperability and data portability, but also for SLAs (see for example C-SIG-SLA 2014), however
these are not mandatory. More recently, there has been a renewed focus
on certification as a means of assurance.
Assurance involves expert practitioners evaluating an CSP against
agreed criteria to improve the degree of confidence of intended users. In
effect, this involves a cloud service provider redesigning their security and
management processes to meet the requirements of a certification scheme,
and then being audited by an independent third party to assess compliance
periodically (Tecnalia 2016). This approach provides an opportunity for
1 UNDERSTANDING TRUST AND CLOUD COMPUTING: AN INTEGRATED…
