Skip to main content
Essay Undergraduate 1,376 words

Risk IT framework implementation for cloud computing security

~7 min read 6 sections
✍️ How to write this paper — guide & tools
Essay 1,376 words

¶ … business organizations incorporate risk management practices of risk IT framework to overcome the security and privacy issues of cloud computing?" The survey questions highlighted the way that managers within these organizations approached this problem from the perspective of philosophy and function. At a fundamental level, most managers understood the need for security, which is the basic starting point. In practice, however, the managers of the different departments noted that not all best practices are adhered to. The solutions that there determined to be the best most common were that security practices are kept in-house, that there are data logs and that there are procedures in place for implementing a hierarchy of access for sensitive data. All companies employ certified, qualified dedicated systems analysts in security, another important consideration. These are the best practices that organizations have to incorporate risk management practices of risk IT framework to overcome the security and privacy issues of cloud computing.

There were also three secondary research questions. The first of these was "How important are the organization's and people's data when deploying cloud computing systems?" The findings indicate that data is considered to be quite important. There are qualified security people in place to ensure a high level of security, and the organization typically maintains its own in-house security protocols. Furthermore, having a hierarchy for access to data is an important element of cloud computing security. That these practices are widespread shows support for the idea that data is an important consideration that it taken into account when deploying cloud computing systems.

The next secondary research question was "To what extent do collaborations exist between business and cloud computing vendors?" The responses indicated that there was some concern with the vendors. This could be because the vendors are out of control of the in-house IT managers, for example. But vendors were frequently subjected to security checks prior to signing contracts, and very few managers expressed support for outsourcing security with respect to the cloud. This desired to keep security issues close, and to avoid leaving security entirely as a vendor role, indicates that most IT managers are uncertain about the security practices of the vendors.

The final secondary research question is "How can risk IT framework be incorporated to the operations domains of cloud computing?" There is a gap in some instances between the best practices of these companies and best practices. Some of these gaps are with fairly simple things, such as passwords. Where these gaps exist there are opportunities to use the risk IT framework in order to improve the risk management practices of these organizations.

Implications

The study provides insight into the risk management practices within a couple of different organizations. These insights show that there are many different areas where risk management practices can be improved. In these organizations, the managers appear to get some of the big things right, like having certified and qualified staff, but they are still getting little things like passwords wrong. These are exactly the sorts of risks that expose many organizations unnecessarily. Effective risk management is not just looking at the big picture risk issues, but the smaller, more refined ones as well. This study shows that there is still some work to do, within these organizations, in terms of improving risk management practices. Using risk IT framework, some of these issues can be overcome, as they relate to cloud computing.

Delimitation

The choice of the population was done on the basis of convenience. This delimitation has ruled out extrapolating the results beyond the population studied. Other organizations, and other industries, may have dramatically different practices than the ones studied here. Given more time and resources, this delimitation could have been eliminated.

The research also specifically omitted asking questions that directly references IT risk framework. The main reason for this was that it would be left to the researcher to examine how well these practices fit the framework, rather than asking the survey respondents to familiarize themselves with this framework and make their own assessments. The differences that might exist in understanding the framework or how it applies to their businesses would introduce too much variability in interpretation to the results for them to be valuable. Thus, this particular line of questioning was not introduced, but rather the paper was structured for this framework to be implemented by the researcher. Importantly, that includes outlining how the organizations in question can introduce the framework going forward to improve their IT security processes with respect to cloud computing.

Significance of the Research to Leadership

The research has some bearing on leadership of IT because leadership is on all elements. First, there is the philosophical element, wherein the leader needs to set the cultural tone for the organization. It is important at that stage that the leader instills a baseline ethic with respect to IT security practices. The research also relates to best practices, which come from leadership. Not only does leadership set out such practices, but leadership is also responsible for ensuring that best practices are adhered to. So there are some rather pragmatic significance to this research for the way that leadership in IT evaluates its security practices with respect to cloud computing.

Recommendations for Future Research

Future research would broaden the scope of this research. What this research contributes is a baseline level of knowledge with respect to the practices of managers within two organizations. To broaden this would bring in a wider sample in terms of the number of organizations, as this would also serve to bring in a bigger population set. That is probably the most important area of future research -- to build on this study, test its findings in other industries and see if these conclusions hold up across other industries, or if they are confined just to this industry.

There is also the remote possibility to do a follow-up study of these managers, to check to see if they have improved their risk management practices in their organizations at some point in the future. This would make an interesting study, but might be constrained by the low number of initial responses. Further attrition of respondents would challenge the findings of such a hypothetical future study.

Conclusions

Risk IT framework is a valuable means of exploring the risk management practices of organizations with respect to cloud computing, in particular evaluating them against best practices. This study shows that many managers have a good understanding of the underlying philosophical issues with respect to security, and take security seriously. But operationally, there are gaps where best practices are not being adhered to. Given that, it is important for managers at these organizations to promote best practices, and sharpen up their security protocols. There is definitely some value in knowing where IT managers stand in the real world, and it will be interesting to see what comes next with respect to this line of inquiry, whether future researchers take the ball and run with it, proverbially, so that they can determine if these findings hold up across all industries, or are just confined to the organizations that were studied here.

189 Words Hidden
Limitations189 words
The study is limited in a couple of ways. First, the survey was conducted among managers of two organizations, so it cannot be extrapolated beyond…
Cite This Paper
PaperDue. (2016). Risk IT framework implementation for cloud computing security. PaperDue. https://www.paperdue.com/essay/findings-and-analysis-it-security-2156769

Always verify citation format against your institution’s current style guide requirements.