15
Assurance
(Trust Building)
Accountability
(Trust Repair)
DECLARATIVE
CONFIRMATIVE
DETECTIVE
PREVENTATIVE
CORRECTIVE
USERS
PROVIDERS
Whole Ecosystem Approach
Inter-disciplinary Co-design
Statement of minimum
service requirements,
standards, policies, and
service levels
Minimum
legal and
regulatory
requirements, standards
and best practices
POLICYMAKERS
& REGULATORS
Terms
and conditions,
standards, business
processes, and underlying
infrastructure and
information systems
Notification system
confirming requirements
met
Feedback mechanisms
Monitoring and reporting
system
Certification and third
party endorsements
Feedback mechanisms
Certification system
Audit system
Trustmark / Trust Label
Alert system for
anomalous behaviour
Risk assessment
Anomaly detection,
analysis and remediation
Risk assessment and
reporting system
Anomalous event
reporting
Notification of
requirement violation
Impact assessment
Access to relevant event
data
Investigation
and cause
diagnosis
Impact assessment
Ongoing reporting and
communication on
investigation
Violation event
reporting
Notification explaining
cause, impact, and
intervention taken
Apology and reparation, if
required
Evaluation of future
recurrence
Incident management incl.
corrective intervention
Liability attribution,
dispute resolution and
reparation incl. hostage
posting
Operations & training
updates
Incident report
Confirmation of corrective
action and resolution
Sanction
New standards, rules and
regulations
Fig. 1.1 An integrated multi-stakeholder framework for building and repairing trust in cloud computing based on assurance and accountability
1 UNDERSTANDING TRUST AND CLOUD COMPUTING: AN INTEGRATED…
Précédent

- 33/166

Suivant