Reference no: EM132919541
The Information Security Community Site is an online companion to this textbook. It contains a wide variety of tools, information, discussion boards, and other features to assist learners.
1. Go to and click the Join or Sign in icon to log in.
2. Click Forums (Discussion) and
3. Click on Security+ Case Projects (6th edition). Read the following case study.
A hospital decided to use cloud computing for processing and storage to save costs. After several months, it was discovered that the cloud provider's storage facilities were compromised and patient information was stolen. The hospital maintained that the cloud provider should be punished and fined for the breach, while the provider responded that it was still the hospital's responsibility under HIPAA to secure patient information and the hospital was ultimately responsible.
Task:
1. Who do you think should be responsible? The cloud provider or the hospital?
2. If the cloud provider is responsible, then should software companies like Microsoft be held liable for a vulnerability in their software that results in a data breach on a Microsoft server in a LAN?
3. Where does the responsibility for the user end and the vendor begin?