1 / 11100%
1
Ethical Data Security and integrity on cloud databases
Donnell Wilson
Liberty University
CSIS325: Database Management Systems
Professor Bird
October 9, 2025
2
Ethical Data Security and integrity on cloud databases
Abstract
The emergence of cloud computing has introduced digital makeup to the data storage and
management architecture, as well as introduced both scalability and flexibility to places
previously unknown to humanity. However, they present severe ethical and technical risks
associated with these technologies, particularly in terms of data confidentiality, integrity, and
availability (CIA). To address the issue of ethical data security and integrity in cloud databases,
the research paper adopts a two-sided approach that combines technical controls with
governance ethics. This will be based on cryptography and the use of zero-trust Architecture
(ZTA), multifactor authentication (MFA), and cryptographic proofs, on the one hand, and
accountability principles based on General Data Protection Regulation (GDPR) compliance and
founded on the principles of stewardship and integrity, on the other hand. The paper shall
address the issues of technical architecture, security mechanisms, and governance mechanisms
of the technical architecture, as well as biblical principles that form a theology of ethical data
management. Lastly, the study concludes that proper data security guarantees required by the
cloud necessitate the integration of high cryptography, governance policies, and moral
principles based on a
Christian worldview.
Cloud computing has concentrated large amounts of both personal and corporate
information in the care of third parties, presenting security and ethical dilemmas that have not
been encountered before. Finally, no other issue, except for technical alternatives, should
compromise the integrity and confidentiality of data stored in such settings, as well as the moral
and ethical management of data (Abdulsalam & Hedabou, 2021). The Moral responsibility,
3
which exceeds what is required by law, should be aware of the rights of data subjects and be
sensitive to the requirements of ethical data security (Pina et al., 2024). These aspects outlined
in the paper will support the position that ethically minded cloud database security should
integrate robust technical solutions- encryption, zero trust, and multi-factor authentication with
ethical moral principles of truthfulness and stewardship through Biblical view of the world (New
International Version, 2011, Proverbs 11:3; 1 Peter 4:10). It is a two-pronged approach, that is
why it is not only safety of the data that is being secured, but also of human dignity as well as
moral responsibility.
Problem Statement
The inherent problem with which this paper will be addressing is the ethical and
technical dilemma of integrity and security of the information with cloud database
environments. As data is deemed to be generated off on premise infrastructures on the shared
cloud, data can be exposed to exfiltration risks, misconfiguration, insider threats, and third-
party weaknesses (Theodoropoulos et al., 2023). According to the Biblical perspective of the
world, the data custodian must ensure that he becomes a responsible custodian of the
information entrusted to him within moral obligation and that technological protection is meted
out in accordance with the moral will. According to 1 Peter 4: 10 each individual should use its
gifts to benefit other human beings as servants of the glorification of the grace of God, present
in its numerous forms.
In this way, the sustainability of the offered statistical data and the safety of its secrets becomes
the gift of good neighbors and stewardship.
4
Purpose Statement
The aim of this study is to investigate the overlapping of ethical accountability, Biblical
accountability, and technical controls as a method of ensuring the security of cloud databases.
Specifically, this paper will look at the technological controls that keep secret, integrity, and
accessibility of information in the clouds intact; will look at how governance and compliance
models, in particular the General Data Protection Regulation (GDPR) professionalize ethical
practices in data management; and how integrity, stewardship, and accountability as ensured
by the Biblical teachings can also be applied to ethical behavior in handling database. The
research
Cloud Database Architectures and Threat Landscape
will demonstrate that cloud data security must be effective in relation to technical
mechanisms and ethical codes founded on integrity and services to other people through the
combination of these dimensions.
Literature Review
The controlled models are designed to operate cloud databases, specifically Database-
asa-Service (DBaaS), which expands shared responsibility and multi-tenancy, significantly
increasing the attack surface (Theodoropoulos et al., 2023). These systems will also be prone to
sources of issues such as data exfiltration, misconfiguration, insider abuse, or unauthorized
cross-tenant access (Abdulsalam & Hedabou, 2021). The latter are particularly significant
threats in a cloud environment, as they are peculiar to the multi-tenant and shared nature of
cloud infrastructure, where the data of varied customers is commonly stored in the same
physical or virtual location. Lack of configuratiendpoints: ult in volumes of data being exposed
using publicly available endpoints; insider misuse consists of an abuser having privileged access
5
to a provider organization; and cross-tenant exposure can occur when there is a breaking of
isolation among virtual machines or containers, thus enabling attackers to then laterally move
through tenants. All these threats undermine confidentiality, integrity and the availability of
information, which are aspects of safe cloud operations.
Technical Controls I: Encryption and Privacy Schemas
Encryption has been the basis on which data protection is anchored. The contemporary
cloud databases are founded on the high demands of encrypted data in the shrouds of secure
keys in the data on-the-rest state and encrypted-data on-the- transit (Abdulsalam & Hedabou,
2021). Homomorphic and searchable encryption, along with other multifaceted protocols, allow
data encrypted information operations and reduce the resulting uncovering at the cost of
reduced performance (Mishra et al., 2025). The fact that lightweight cryptographic programs
can minimize the latency even in a distributed architecture is also beneficial to ensure that it is
possible to perform operates securely (Mohammed et al., 2023). The code ninety of securing
the passwords by means of the hardware security modules (HSMs) would ensure that not even
the cloud providers will be able to gain unilateral access to the decryption keys.
Technical Controls II: Identity, Access, and Zero-Trust Governance
Zero Trust Architecture (ZTA) is a design that replaces the traditional model of the trust,
which is perimeter based, with a continuous validation design. It also presupposes that no
things, both external and internal, can be trusted unconditionally (Adahman et al., 2022). The
most important aspects of ZTA are micro-segmentation, the field of device posture testing, and
the analytics of telemetry (Theodoropoulos et al., 2023). The systematic means of identity
management and data governance integration may be received with the assistance of the help
of ZTA maturity models (Yeoh et al., 2024), as the means of measuring the organization
6
preparedness to it. Regardless of its complexities, ZTA causes huge destruction to the outcome
of breach on a long-term basis and consolidates governance stability.
Technical Controls III: Multi-Factor Authentication and Anomaly Detection
Authentication hardening is another defensive feature, and it is very significant. One
form of account compromise involves behavioral analytics, step-up authentication, and device
context used to compromise accounts, and another is called account compromise, whereby
adaptive multi-factor authentication (MFA) is used to supplement the account compromise
(Mostafa et al., 2023). The additional weaknesses including man-in-the-middle attacks are
overcome by the use of multilayer authentication model, which employs AES encryption. Both
session governance and Risk-based reauthentication apply ZTA concepts of continuous
verification at the user level.
Ensuring Data Integrity in Untrusted Environments
The security of the information stored in unstunstate-of-the-art, uncontrollable systems
necessitates a verifiable accounting of ththe e identification of the information. Cryptographic
schemes, such as Proofs of Retrievability (PoR) and Provable Data Possession (PDP), can
guarantee that the outsourced data remains untouched (Adahman et al., 2022). Checks and
random spot checks of the cryptography are built upon integrity checks and scheduled checks,
and responses to the cryptographic system of logging taking place, which enhance
accountability.
Compliance, Ethical Duty, and Governance
Data governance should be consistent with regulatory laws, such as the GDPR, including
the purpose limitation and minimization requirements, as well as the requirement that data
processing be lawful and transparent. The study of Swedish case studies on public organizations
7
shows that the majority of them were encountering the same challenges in obtaining full
compliance, and it was normally due to the lack of clear contracts or poor anonymization
(Issaoui et al., 2023). Besides its role in the area of compliance, data ethics should become a
subset of the idea of corporate sustainability and Environmental, Social, and Governance (ESG)
(Balboni & Francis, 2024). Access controls, minimized retention, and transparency are examples
of the ethical principles that require the input of database administrators (DBAs).
Auditing, Observability, and Incident Response
Comprehensive telemetry and database audit logs provide real-time insights into
security events. Security Information and Event Management (SIEM) and User and Entity
Behavior Analytics (UEBA) systems are required to identify the anomalies of the database
activity (Theodoropoulos et al., 2023). The controls, such as encryption, least-privilege roles,
and network segmentation, are all similar to environments in policy-as-code. Incident response
must also include credential rotation, integrity verification, and legal notification procedures,
which need to be within GDPR timeframes.
Implications of Research
To apply a dual ethical-technical framework, professionals working in the industry will
build trust, mitigate the effects of breach, and benefit long-term data management. Managers
are advised to incorporate the principles of zero-trust, use MFA in privileged accounts, and
implement the privacy-saving models of analytics. Ethical governance answers the call to
corporate responsibility to the expectations of society on data integrity.
Biblical Worldview Implications
Ethically, data security is in line with Christian virtues of stewardship, honesty and
service. According to 1 Peter 4:10, a person who receives information about the others is a
8
steward whom he or she is expected to safeguard the interest of his or her neighbor. Proverbs
11:3 makes us remember that integrity of the upright will lead them, which highlights the
ethical need to be honest and transparent in the digital systems. The moral aspects of digital
data practices are therefore the manifestations of obedience and moral uprightness in the
digital era.
Biblical Worldview Integration
Proponents of the Biblical worldview promote the aspects of ethical consistency and
moral accountability in data handling. Stewardship requires the information (personal, as well
as organizational) to be preserved due to a respect towards human dignity (New International
Version, 2011, 1 Peter 4:10). The honesty of telling the truth, being open and honest to
encourage the value of telling the truth as in Proverbs 11:3, is what is involved in truthful
reporting as well as disclosures of incidents and fair ruling. All these virtues will total to the
information integrity and compliance ethics. The place where ethics-based conduct will
supplement the technological ability is the environment, which is a bundle of moral regulation
and systemic regulation.
Expected Challenges and Limitations
Cryptographic and governance models are the most protective measures, although come
up with issues related to operation. It is possible that privacy-saving encryption protocols that
are fully homomorphic can require computation costs to the performance (Mishra et al., 2025;
Mohammed et al., 2023). ZTA is a powerful project, which must be implemented at once with
the assistance of maturity models (Yeoh et al., 2024). In addition, institutions must have to
make a balance between trust in cloud providers and advanced technical assurance, such as key
in the hands of customers and third-party audits.
9
Conclusion
The protection of information within the databases of the clouds is not an ethical and
legal duty only but also a legal requirement. Attempts to combine the technological controls
(encryptions, MFA, zero trust, and cryptographic proofs) with the existing governance structures
must be undertaken to meet the accountability and transparency goals. By being informed by
the Biblical principles of honesty and stewardship, the data management process can be seen
not as a form of compliance but as an obligation of moral obligation. In the future, a study into
better cryptographic solutions and how to instill ESG consistent ethics in data governance would
be studied.
10
References
Abdulsalam, Y. S., & Hedabou, M. (2021). Security and privacy in cloud computing: technical
review. Future Internet, 14(1), 11. https://www.mdpi.com/1999-5903/14/1/11
Adahman, Z., Malik, A. W., & Anwar, Z. (2022). An analysis of zero-trust architecture and its cost-
effectiveness for organizational security. Computers & Security, 122, 102911.
https://www.sciencedirect.com/science/article/abs/pii/S0167404822003042
Balboni, P., & Francis, K. E. (2024). Data ethics and digital sustainability: Bridging legal data
protection compliance and ESG for a responsible data-driven future. Journal of
Responsible Technology, 100099.
https://www.sciencedirect.com/science/article/pii/S2666659624000258
Issaoui, A., Örtensjö, J., & Islam, M. S. (2023). Exploring the General Data Protection Regulation
(GDPR) compliance in cloud services: insights from Swedish public organizations on
privacy compliance. Future Business Journal, 9(1), 107.
https://fbj.springeropen.com/articles/10.1186/s43093-023-00285-2
Mishra, K. N., Lal, R. K., Barwal, P. N., & Mishra, A. (2025). Advancing Data Privacy in Cloud
Storage: A Novel Multi-Layer Encoding Framework. Applied Sciences, 15(13), 7485.
https://www.mdpi.com/2076-3417/15/13/7485
Mohammed, S., Nanthini, S., Krishna, N. B., Srinivas, I. V., Rajagopal, M., & Kumar, M. A. (2023).
A new lightweight data security system for data security in the cloud computing.
Measurement: Sensors, 29, 100856.
https://www.sciencedirect.com/science/article/pii/S2665917423001927
Mostafa, A. M., Ezz, M., Elbashir, M. K., Alruily, M., Hamouda, E., Alsarhani, M., & Said, W.
11
(2023). Strengthening cloud security: an innovative multi-factor multi-layer
authentication framework for cloud user authentication. Applied Sciences, 13(19),
10871.
https://www.mdpi.com/2076-3417/13/19/10871
New International Version. (2011). The Holy Bible. Zondervan.
https://www.biblegateway.com/passage/?search=Proverbs%2011%3A3&version=NIV
Pina, E., Ramos, J., Jorge, H., Váz, P., Silva, J., Wanzeller, C., ... & Martins, P. (2024). Data privacy
and ethical considerations in database management. Journal of Cybersecurity and
Privacy, 4(3), 494-517. https://www.mdpi.com/2624-800X/4/3/24
Theodoropoulos, T., Rosa, L., Benzaid, C., Gray, P., Marin, E., Makris, A., & Tserpes, K.
(2023). Security in cloud-native services: A survey. Journal of Cybersecurity and
Privacy, 3(4), 758-793. https://www.mdpi.com/2624-800X/3/4/34
Yeoh, W., Liu, M., Shore, M., & Jiang, F. (2023). Zero trust cybersecurity: Critical success factors
and A maturity assessment framework. Computers & Security, 133, 103412.
https://www.sciencedirect.com/science/article/pii/S016740482300322X
Students also viewed