Academic Integrity: tutoring, explanations, and feedback — we don’t complete graded work or submit on a student’s behalf.

A hospital decided to use cloud computing for processing and storage in order to

ID: 3691409 • Letter: A

Question

A hospital decided to use cloud computing for processing and storage in order to save costs.After several months it was discovered that the cloud provider's storage facilities were compromised and patient information was stolen. The hospital maintained that the cloud provider should be punished and fined for the breach, while the provider responded that it was still the hospital's responsibility under HIPAA to secure patient information and the hospital was ultimately responsible.Who do you think should be responsible? The cloud provider or the hospital? If the cloud provider is responsible, then should software companies like Microsoft be held liable for a vulnerability in their software that results in a data breach on a Microsoft server in a LAN? Where does the responsibility for the user end and the vendor begin?

Explanation / Answer

Responsibility rest with hospital to secure patients information

Customers control over public cloud computing services increases as we move down the computing stack. Infrastructure as a Service (IaaS) offering the most control and Software as a Service (SaaS) offering little or no control . The same goes for security responsibilities in the cloud: With SaaS, the responsibility to secure the platform and infrastructure clearly falls on the provider.

But when we move futher down the stack things get murky . When it comes to IaaS, there is no clear-cut line between provider and user security responsibilities. It's customer responsibility to define the lines

"It's really important that cloud tenants or customers understand this is definitely a shared responsibility from a governance perspective, from a control perspective, from a management perspective," and to implement the appropriate controls, cloud tenants must understand where security gaps exist. "

Hire Me For All Your Tutoring Needs
Integrity-first tutoring: clear explanations, guidance, and feedback.
Drop an Email at
drjack9650@gmail.com
Chat Now And Get Quote