Controls and Governance for Cloud Computing

Of late, cloud computing has grown from being a promising business concept to one of the fastest growing segments of the IT industry. Companies have recognised that by simply tapping into the cloud they can gain fast access to best-of-breed business applications or drastically boost their infrastructure resources, all at negligible cost. But as more and more information on individuals and companies is placed in the cloud, concerns are beginning to grow about just how safe an environment it is. However, Cloud Computing is fraught with security risks and more and more concerns are being raised on the risks involved.

To help organizations worldwide get the most value from the cloud, ISACA has issued a new guide outlining how to implement effective controls and governance for cloud computing.

 

According to the ISACA guide, when enterprises decide to use cloud computing for IT services, business processes are impacted and governance becomes critical to:

 

Effectively manage increasing risk

 

Ensure continuity of critical business processes that now extend beyond the data center

 

Communicate clear enterprise objectives internally and to third parties

 

Adapt effectively

 

Facilitate continuity of IT knowledge, which is essential to sustain and grow the business

 

Handle myriad regulations.

 

The guide notes that enterprises must ask the following key questions for proper governance of cloud computing:

 

What is the enterprise’s expected availability?

 

How are identity and access managed in the cloud?

 

Where will the enterprise’s data be located?

 

What are the cloud service provider’s disaster recovery capabilities?

 

How is the security of the enterprise’s data managed?

 

How is the whole system protected from Internet threats?

 

How are activities monitored and audited?

 

What type of certification or assurances can the enterprise expect from the provider?

 

The e-book form of “IT Control Objectives for Cloud Computing” is available for free download by ISACA members and for purchase by non-members at US $50.