A Cloud Governance Framework for Cloud Computing : An Information Security Governance Perspective to Protect Cloud Users
Ahmad, Rizwan · ResearchSpace (University of Auckland) · 2013
The cloud computing is an emerging technological solution for harbouring data assets in publicly available data centres that supports multi-tenancy and virtualization, providing cost effective solutions to cloud users. The cloud computing has followed an uncertain path riddled with information security issues from the cloud user perspective. Typically, the cloud user is the owner of data assets and does not have the control to apply their security controls on the platform of cloud service provider. These controls are aggravated by transborder flow of data assets in different jurisdictions where cloud service provider resides, thus creating more complexity through distance, conflict of laws and the absence of cloud user rights. This leads to a gap and lack of trust, and corresponding uncertainty in the cloud environment. The study attempts to investigate this phenomenon using a multi-disciplinary approach and come up with a solution in the form of a governance framework that will ease some of the problems. The study takes an Actor Network theory (ANT) and Transdisciplinary Research approach to explore the issues in cloud security and improves the conceptualized governance framework through a longitudinal study from different dimensions to assure the long term viability of the findings. The study divides the research in two phases. The Phase 1 builds the conceptual framework by introducing the Joint Governance Board that extends the information security governance practices on cloud platform. It brings two contributions to the security governance literature. The first contribution is inception of collaborative platform that eases the security implementation by introducing various artefacts available in security standards reducing the influence of cloud service provider articulated in literature. The second contribution is joint governance board that balances the information security governance on cloud platform by acknowledging principles of fairness and mutual understanding. The phase 2 uses ANT to bring the cloud governance framework in the realm of social discourse to validate and improve the framework. With the combination of Transdisciplinary research methodology, the multi-disciplinary research outcome is aligned symmetrically to give holistic shape to the cloud governance framework. The study uses the three methods of ANT; Translation, follow the actors and inscription. All of these methods separately analyse and synthesize the results to corroborate the conceptual framework. The study also uses the triangulation of methods to confirm the findings and suggest improvements. The study brings theoretical and practical contributions by amalgamating the results projected through the triangulation. The study contributed cloud governance framework by aligning the technical, social and legal to implement the information security governance and to protect the rights of the cloud user holistically. The study also contributes through its diverse research methodological and provides guidance to validate the findings rigorously through qualitative method triangulation. The study offers a holistic cloud governance approach that is gradually improved and refined through peer review, recursive ANT, social discourse and triangulation.