12
rule-based trust to develop and, in situations where the providers of the
certification are trusted, the potential for trust transfer to occur. In a
report for the European Commission published in 2018, Tecnalia identified over 20 such schemes, the most popular being compliance with ISO
27001; others included CSA Star, PCI-DSS, ENISA-CCM and the SOC
(ISAE-3402) (Tecnalia 2016). A major limitation of the certification
approach is the timeliness and the depth of the audit. In-depth audits may
only take place every three years with light-touch reviews annually.
Similarly, given the complexity of cloud computing, the level of detail that
a certification or an auditor can go to is limited.
Three common methods are used to communicate trust in CSPs—
website design, feedback mechanisms, and third party endorsements
(Lynn et al. 2016). There is a substantial body of literature on the direct
and indirect impact of visual website appearance on trust including colour
choice and design symmetry which represent powerful heuristic cues for
trust. However, aesthetic preferences in website design tend to vary across
demographic characteristics and thus may have limited practical utility for
CSPs trying to communicate trust (Cyr et al. 2010; Tuch et al. 2010).
Feedback mechanisms or reputation systems are an increasingly popular
alternative mechanism for communicating trust. As cloud and API marketplaces have emerged, such as Salesforce AppExchange, Microsoft Azure
Marketplace and RapidAPI, so too have market-driven feedback systems
within these marketplaces. Ratings, reviews, and vendor ecosystem status
all act as a signal to consumers that the vendor has an incentive to behave
in an appropriate manner and that they have been informally certified by
previous consumers (Pavlou and Gefen 2004). Again, these mechanisms
are likely to impact trust by providing a level of structural assurance and
cues regarding the rules governing trustworthy behaviour. Independently
of the cloud sector, a plethora of general reputation and review systems,
such as Feefo and Trust Pilot, have emerged in recent years that seek to
provide prospective customers, both business-to-business (B2B) and
business- to-consumer (B2C), with similar signals on an independent basis
by aggregating ratings, surveys and reviews (Banerjee et al. 2020).
Increasingly, these are integrated not only in to a vendor’s website but
into search engine ranking algorithms, providing additional incentives for
vendors to behave. Notwithstanding their widespread and increasing use,
feedback and reputation systems have been criticised for their vulnerability
to false, manipulated or biased feedback (Sabater and Sierra 2005).
T. LYNN ET AL.
rule-based trust to develop and, in situations where the providers of the
certification are trusted, the potential for trust transfer to occur. In a
report for the European Commission published in 2018, Tecnalia identified over 20 such schemes, the most popular being compliance with ISO
27001; others included CSA Star, PCI-DSS, ENISA-CCM and the SOC
(ISAE-3402) (Tecnalia 2016). A major limitation of the certification
approach is the timeliness and the depth of the audit. In-depth audits may
only take place every three years with light-touch reviews annually.
Similarly, given the complexity of cloud computing, the level of detail that
a certification or an auditor can go to is limited.
Three common methods are used to communicate trust in CSPs—
website design, feedback mechanisms, and third party endorsements
(Lynn et al. 2016). There is a substantial body of literature on the direct
and indirect impact of visual website appearance on trust including colour
choice and design symmetry which represent powerful heuristic cues for
trust. However, aesthetic preferences in website design tend to vary across
demographic characteristics and thus may have limited practical utility for
CSPs trying to communicate trust (Cyr et al. 2010; Tuch et al. 2010).
Feedback mechanisms or reputation systems are an increasingly popular
alternative mechanism for communicating trust. As cloud and API marketplaces have emerged, such as Salesforce AppExchange, Microsoft Azure
Marketplace and RapidAPI, so too have market-driven feedback systems
within these marketplaces. Ratings, reviews, and vendor ecosystem status
all act as a signal to consumers that the vendor has an incentive to behave
in an appropriate manner and that they have been informally certified by
previous consumers (Pavlou and Gefen 2004). Again, these mechanisms
are likely to impact trust by providing a level of structural assurance and
cues regarding the rules governing trustworthy behaviour. Independently
of the cloud sector, a plethora of general reputation and review systems,
such as Feefo and Trust Pilot, have emerged in recent years that seek to
provide prospective customers, both business-to-business (B2B) and
business- to-consumer (B2C), with similar signals on an independent basis
by aggregating ratings, surveys and reviews (Banerjee et al. 2020).
Increasingly, these are integrated not only in to a vendor’s website but
into search engine ranking algorithms, providing additional incentives for
vendors to behave. Notwithstanding their widespread and increasing use,
feedback and reputation systems have been criticised for their vulnerability
to false, manipulated or biased feedback (Sabater and Sierra 2005).
T. LYNN ET AL.
