This audit and security program created by ISACA is a tool and a template that will be used as a roadmap for conducting an audit process for Cloud Computing services.
This document was developed to be used as an examination tool and starting point, can be adapted by professionals and auditors and is not intended to be a checklist or questionnaire.The objective of the audit to be cloud services shall:
Provide stakeholders with an assessment of the effectiveness of internal controls of the services and security provided by the cloud providerIdentify internal control deficiencies within the customer's organization and their interrelationship with the service providerProvide audit stakeholders with an assessment of the quality and their ability to rely on the service provider's certifications, in terms of internal controls. This guide is not designed to replace audits of specific process applications and excludes assurance of an application's functionality.The review will focus on:
Cloud computing governanceContract compliance between provider and customerControlling specific cloud computing issuesAir auditors and security professionals are expected to modify this document for the environment in which a warranty process is being conducted. IT and audit professionals are supposed to have the necessary subject matter expertise to get the job done.The full document can be downloaded from the ISACA website.
Cristian from the Segu-Info Newsroom
Authors: Computer Security News