{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/97572"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/97572","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Privacy and security in the clouds: IT security and privacy standards in the EU and US","abstract":"Cloud computing represents a revolutionary service model for accessing information technology (IT) services, and an opportunity for governments to reduce maintainance costs of IT infrastructure. However, relying on commercial cloud services may prove challenging for privacy and security if cloud service providers cannot guarantee adequate standards for their services. In this thesis, I analyze four IT security standards comparing them alongside each other. ISO/IEC 27001 and SOC 2 are two international IT frameworks issued by non-government organizations and available since 2005. FedRAMP and C5 are two more recent cloud-specific standards, respectively issued by the US and German governments. Examining the four standards in comparison, and evaluating their completeness and adequacy in guaranteeing information assurance in cloud environments, I question whether they really represent an improvement in cloud security, what are their shortcomings, and ultimately the necessity of new cloud security standards in the already crowded IT security landscape. I combine a broad contextual analysis with empirical results to help understand the reasons for creating C5, and shed lights on its role in the EU political agenda.","abstract_html":"Cloud computing represents a revolutionary service model for accessing information technology (IT) services, and an opportunity for governments to reduce maintainance costs of IT infrastructure. However, relying on commercial cloud services may prove challenging for privacy and security if cloud service providers cannot guarantee adequate standards for their services. In this thesis, I analyze four IT security standards comparing them alongside each other. ISO/IEC 27001 and SOC 2 are two international IT frameworks issued by non-government organizations and available since 2005. FedRAMP and C5 are two more recent cloud-specific standards, respectively issued by the US and German governments. Examining the four standards in comparison, and evaluating their completeness and adequacy in guaranteeing information assurance in cloud environments, I question whether they really represent an improvement in cloud security, what are their shortcomings, and ultimately the necessity of new cloud security standards in the already crowded IT security landscape. I combine a broad contextual analysis with empirical results to help understand the reasons for creating C5, and shed lights on its role in the EU political agenda.","abstract_has_math":false,"creators":["Di-Giulio, Carlo"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.A.","degree_level":"Thesis","degree_discipline":"European Union Studies","degree_department":null,"school":null,"contributors":["Bashir, Masooda N.","Larivé, Maxime H. A."],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2017,"date_issued":"2017-08-10T19:51:56Z","date_published":"2017-08-10T19:51:56Z","updated_at":"2026-07-22T22:24:34Z","subjects":["Privacy","Security","European Union (EU)","Cloud","Cloud Computing Compliance Controls Catalogue (C5)","Federal Risk Authorization Management Program (FedRAMP)","International Organization for Standardization (ISO)","System and Organization Controls (SOC) 2"],"languages":["en"],"rights":["Copyright 2017 Carlo Di-Giulio"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/97572","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Bashir, Masooda N.","Larivé, Maxime H. A."]},{"key":"dc:creator","label":"Author","values":["Di-Giulio, Carlo"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2017-08-10T19:51:56Z","2019-08-11T09:15:28Z","2017-04-17","2017-05"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["European Union Studies"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.A."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Privacy","Security","European Union (EU)","Cloud","Cloud Computing Compliance Controls Catalogue (C5)","Federal Risk Authorization Management Program (FedRAMP)","International Organization for Standardization (ISO)","System and Organization Controls (SOC) 2"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2017 Carlo Di-Giulio"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/97572"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Cloud computing represents a revolutionary service model for accessing information technology (IT) services, and an opportunity for governments to reduce maintainance costs of IT infrastructure. However, relying on commercial cloud services may prove challenging for privacy and security if cloud service providers cannot guarantee adequate standards for their services. In this thesis, I analyze four IT security standards comparing them alongside each other. ISO/IEC 27001 and SOC 2 are two international IT frameworks issued by non-government organizations and available since 2005. FedRAMP and C5 are two more recent cloud-specific standards, respectively issued by the US and German governments. Examining the four standards in comparison, and evaluating their completeness and adequacy in guaranteeing information assurance in cloud environments, I question whether they really represent an improvement in cloud security, what are their shortcomings, and ultimately the necessity of new cloud security standards in the already crowded IT security landscape. I combine a broad contextual analysis with empirical results to help understand the reasons for creating C5, and shed lights on its role in the EU political agenda.","Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2019-05-01","The student, Carlo Di-Giulio, accepted the attached license on 2017-04-14 at 16:50.","The student, Carlo Di-Giulio, submitted this Thesis for approval on 2017-04-14 at 16:58.","This Thesis was approved for publication on 2017-04-17 at 14:49.","DSpace SAF Submission Ingestion Package generated from Vireo submission #10770 on 2017-08-10 at 14:30:46","Made available in DSpace on 2017-08-10T19:51:56Z (GMT). No. of bitstreams: 2 DI-GIULIO-THESIS-2017.pdf: 1840762 bytes, checksum: 1152dedc8da3c3e5932b6d4e82f46737 (MD5) LICENSE.txt: 4212 bytes, checksum: c4eef3354c2b8181a2af0f287ecd2ca8 (MD5) Previous issue date: 2017-04-17","Embargo set by: Colleen Fallaw for item 102625 Lift date: 2019-08-10T21:25:30Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Limited Restriction Lifted for Item 102625 on 2019-08-11T09:15:28Z."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Privacy and security in the clouds: IT security and privacy standards in the EU and US"]}]}],"canonical_facts":{"dc:contributor":["Bashir, Masooda N.","Larivé, Maxime H. A."],"dc:creator":["Di-Giulio, Carlo"],"dc:date":["2017-08-10T19:51:56Z","2019-08-11T09:15:28Z","2017-04-17","2017-05"],"dc:description":["Cloud computing represents a revolutionary service model for accessing information technology (IT) services, and an opportunity for governments to reduce maintainance costs of IT infrastructure. However, relying on commercial cloud services may prove challenging for privacy and security if cloud service providers cannot guarantee adequate standards for their services. In this thesis, I analyze four IT security standards comparing them alongside each other. ISO/IEC 27001 and SOC 2 are two international IT frameworks issued by non-government organizations and available since 2005. FedRAMP and C5 are two more recent cloud-specific standards, respectively issued by the US and German governments. Examining the four standards in comparison, and evaluating their completeness and adequacy in guaranteeing information assurance in cloud environments, I question whether they really represent an improvement in cloud security, what are their shortcomings, and ultimately the necessity of new cloud security standards in the already crowded IT security landscape. I combine a broad contextual analysis with empirical results to help understand the reasons for creating C5, and shed lights on its role in the EU political agenda.","Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2019-05-01","The student, Carlo Di-Giulio, accepted the attached license on 2017-04-14 at 16:50.","The student, Carlo Di-Giulio, submitted this Thesis for approval on 2017-04-14 at 16:58.","This Thesis was approved for publication on 2017-04-17 at 14:49.","DSpace SAF Submission Ingestion Package generated from Vireo submission #10770 on 2017-08-10 at 14:30:46","Made available in DSpace on 2017-08-10T19:51:56Z (GMT). No. of bitstreams: 2 DI-GIULIO-THESIS-2017.pdf: 1840762 bytes, checksum: 1152dedc8da3c3e5932b6d4e82f46737 (MD5) LICENSE.txt: 4212 bytes, checksum: c4eef3354c2b8181a2af0f287ecd2ca8 (MD5) Previous issue date: 2017-04-17","Embargo set by: Colleen Fallaw for item 102625 Lift date: 2019-08-10T21:25:30Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Limited Restriction Lifted for Item 102625 on 2019-08-11T09:15:28Z."],"dc:format":["application/pdf"],"dc:identifier":["http://hdl.handle.net/2142/97572"],"dc:language":["en"],"dc:rights":["Copyright 2017 Carlo Di-Giulio"],"dc:subject":["Privacy","Security","European Union (EU)","Cloud","Cloud Computing Compliance Controls Catalogue (C5)","Federal Risk Authorization Management Program (FedRAMP)","International Organization for Standardization (ISO)","System and Organization Controls (SOC) 2"],"dc:title":["Privacy and security in the clouds: IT security and privacy standards in the EU and US"],"dc:type":["text"],"thesis:degree_discipline":["European Union Studies"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.A."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:24:34Z"}