62
described as human constructed abstract notions which vary according to
context and other factors (Lowry et  al. 2017). For the purpose of the
chapter, both concepts are defined and discussed in terms of their pertinence to cloud.
4.2.1
Information Security
Information security refers to the preservation of the three tenets of security; the confidentiality of information, the integrity information, and the
availability of information, while also considering other risks such as reliability, authenticity, and accountability (Pearson 2012; ISO 2005). In the
cloud computing context, the key security vulnerabilities warranting consideration include trust, encryption, multi-tenancy, and reliability
(Ramireddy et al. 2010). In addition, these vulnerabilities result in serious
security risks related to data integrity, confidentiality, data loss, and data
authentication (Subashini and Kavitha 2011). Research has provided some
initial support for the relevance of these risks. For example, in their study
of the factors impacting public sector cloud adoption in South Africa,
Scholtz et al. (2016) found that data accessibility was a concern for 90% of
participants and cyberattacks represented a concern for 76% for participants. Security and privacy are inextricably linked, as any security incident
puts the privacy of the individual’s data at risk (Sonehara et al. 2011). In
addition, these security issues may lead to intangible risks or concerns such
as loss in confidence of the reliability of the cloud and fears around access
to personal data (Paquette et al. 2010).
4.2.2 Information Privacy
Privacy has been the subject of academic discourse for over two centuries
in disciplines such as law, sociology and IS. Indeed, the first academic discussions of privacy are often credited to the 1890 Harvard Law Review
article by Warren and Brandeis, in which they discuss privacy in terms of
the need to balance individuals’ rights to be free from intrusion with the
information needs of society (Warren and Brandeis 1890). From a sociological perspective, the seminal definition of privacy was developed by
Alan Westin (1967, p. 7), who described privacy as “the claim of individuals, groups, or institutions to determine for themselves when, how, and to
what extent information about them is communicated to others.” These
seminal works are the building blocks of conceptualisations across
G. FOX
Précédent

- 80/166

Suivant