13
A third approach to communicating trust in CSPs involves the use of
assurance seals or trustmarks that combine certification and communication to dispel consumer concerns about risk and communicate adherence
with best practice, a code of conduct, or certification scheme using a thirdparty mark or symbol (Aiken and Boush 2006). Like certification, trustmark holders are typically subject to periodic third party verification.
However, in addition to recognition and lack of information depth, trustmarks suffer from the same limitations as certification in general. They have
been criticised for reliance on human intervention, limited scope, timeliness, lacking warranties, and subject to co-optation risk (Aiken et al. 2003).
Technological innovation to build trust in cloud computing largely
revolves around designing clouds that meet the three pillars of trustworthy computing—security and privacy, reliability, and business integrity
(Mundie et al. 2002). Chapter 7 discusses this topic in detail. It is important to note, however, that technical innovation in trustworthy computing
overwhelmingly focuses on the first two pillars, security and privacy, and
reliability. Research on the former focuses on the provision of effective
attack resilient systems, typically using encryption techniques of increasing
strength and complexity. Reliability research focuses on the design, monitoring, and measurement of highly reliable systems. Both domains are
largely hidden from end-users. Business integrity is more nuanced and
suffers from a lack of inter-disciplinary research. As such, it focuses largely
on monitoring key service level metrics and ranking services based on this
data. One of the main limitations of purely technological approaches, is
that by and large, customers are human. Their decisions to trust are based
on a vast array of conscious and subconscious signals that are often forgotten about in purely technological approaches and solutions.
In attempt to address this gap and marry the various approaches to
mitigating trust issues in cloud computing, we have previously proposed
an active dynamic online trust label (Lynn et al. 2014; Lynn et al. 2016;
Emeakaroha et al. 2016; van der Werff et al. 2019b). Inspired by nutritional labels, these labels present consumers with corporate information,
policies, and historic and near real-time service level metrics based on data
from CSP monitoring systems (Emeakaroha et al. 2016). The system can
allow for third party independent certification and could allow for corporate attestation using digital signatures. Based on an experimental study
with 227 business decision makers, the proposed cloud trust label communicated trustworthiness effectively (van der Werff et al. 2019b). While
these results are promising, such a system requires widespread support to
be effective. Until then, it remains an academic exercise.
1 UNDERSTANDING TRUST AND CLOUD COMPUTING: AN INTEGRATED…
A third approach to communicating trust in CSPs involves the use of
assurance seals or trustmarks that combine certification and communication to dispel consumer concerns about risk and communicate adherence
with best practice, a code of conduct, or certification scheme using a thirdparty mark or symbol (Aiken and Boush 2006). Like certification, trustmark holders are typically subject to periodic third party verification.
However, in addition to recognition and lack of information depth, trustmarks suffer from the same limitations as certification in general. They have
been criticised for reliance on human intervention, limited scope, timeliness, lacking warranties, and subject to co-optation risk (Aiken et al. 2003).
Technological innovation to build trust in cloud computing largely
revolves around designing clouds that meet the three pillars of trustworthy computing—security and privacy, reliability, and business integrity
(Mundie et al. 2002). Chapter 7 discusses this topic in detail. It is important to note, however, that technical innovation in trustworthy computing
overwhelmingly focuses on the first two pillars, security and privacy, and
reliability. Research on the former focuses on the provision of effective
attack resilient systems, typically using encryption techniques of increasing
strength and complexity. Reliability research focuses on the design, monitoring, and measurement of highly reliable systems. Both domains are
largely hidden from end-users. Business integrity is more nuanced and
suffers from a lack of inter-disciplinary research. As such, it focuses largely
on monitoring key service level metrics and ranking services based on this
data. One of the main limitations of purely technological approaches, is
that by and large, customers are human. Their decisions to trust are based
on a vast array of conscious and subconscious signals that are often forgotten about in purely technological approaches and solutions.
In attempt to address this gap and marry the various approaches to
mitigating trust issues in cloud computing, we have previously proposed
an active dynamic online trust label (Lynn et al. 2014; Lynn et al. 2016;
Emeakaroha et al. 2016; van der Werff et al. 2019b). Inspired by nutritional labels, these labels present consumers with corporate information,
policies, and historic and near real-time service level metrics based on data
from CSP monitoring systems (Emeakaroha et al. 2016). The system can
allow for third party independent certification and could allow for corporate attestation using digital signatures. Based on an experimental study
with 227 business decision makers, the proposed cloud trust label communicated trustworthiness effectively (van der Werff et al. 2019b). While
these results are promising, such a system requires widespread support to
be effective. Until then, it remains an academic exercise.
1 UNDERSTANDING TRUST AND CLOUD COMPUTING: AN INTEGRATED…
