Triangulation Theory: an Approach to Mitigate Governance Risks in Clouds

نویسندگان

  • Rizwan Ahmad
  • Lech Janczewski
چکیده

Cloud computing is a business concept that delivers technology “as a service”. Its lower cost of operation is the main economic driver for consumers and enterprises. The major obstruction to its adoption is security and governance risks inherent in its transnational nature. These risks are associated with relative change of governance level within the cloud service layers during the relationship between the customer and cloud provider in public cloud computing (PCC). The responsibility and authority of both the entities differs in each layer bifurcating influence of due care and due diligence. The existing internationally recognized security standards International Organization for Standardization (ISO 27001/2), Control Objectives for Information and Related Technology (COBIT) etc do not handle cloud computing domains from every aspect. Similarly, due to transnational nature of PCC, legislative acts of one country cannot get dejure recognition in different jurisdiction. These variations incapacitate PCC from achieving assurance and governance level to sustain cloud security. The paper will present a theoretical model to develop common criteria using triangulation of service layers, security standards and statutory laws, essential to maintain governance and security. Keywords-Governance, Cloud Computing, Security, Assurance

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A Panel Analysis of Good Governance and FDI on Economic Growth in MENA Region

The paper focuses on regional trade agreements and economic co-operation and develops a new appropriate approach to study their impact on growth and trade. The approach is based on an endogenous trade-growth theory and novelly specified in an economic integration (expenditure) framework which is the conceptual foundation of regional trade agreements. Importantly, it also appropriately takes int...

متن کامل

Identifying the factors affecting the governance of the National Iranian Oil Company with a corporate sustainability approach

The purpose of this study was to identify the modt important factors affecting corporate governance with a corporate sustainability approach, according to the nature of operational activities of the National Iranian Oil Company. Initially, by conducting theoretical studies including articles, G4 Global Reports Guide, and governance patterns of the worldchr('39')s major oil companies, the factor...

متن کامل

Risks and Opportunities of Reforms Putting Primary Care in the Driver’s Seat; Comment on “Governance, Government, and the Search for New Provider Models”

Recognizing the advantages of primary care as a means of improving the entire health system, this text comments on reforms of publicly funded primary health centers, and the rapid development of private forprofit providers in Sweden. Many goals and expectations are connected to such reforms, which equally require critical analyses of scarce resources, professional trust/motivation and business ...

متن کامل

Good corporate governance in Nigeria: Antecedents, propositions and peculiarities ¬リニ

Relying on an alternative theoretical framework (i.e. institutional theory), rather than the dominant agency theory, this paper examines the connections between corporate governance mechanisms and good practices, as informed by an empirical and contextual analysis. On the basis of research methods triangulation, this study presents nine specific antecedents of good corporate governance in weak ...

متن کامل

On the Emergence of Shadow IT - a Transaction Cost-Based Approach

Information Technology (IT) used for business processes is not only provided by the organization’s IT department. Business departments and users autonomously implement IT solutions, which are not embedded in the organizational IT service management. This increasingly occurring phenomenon is called Shadow IT. The various opportunities and risks of Shadow IT challenge organizations and call for a...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2010