CLOUD COMPUTING for Construction Accounting BY BRIAN J. THOMAS

Save this PDF as:
 WORD  PNG  TXT  JPG

Size: px
Start display at page:

Download "CLOUD COMPUTING for Construction Accounting BY BRIAN J. THOMAS"

Transcription

1 CLOUD COMPUTING for Construction Accounting BY BRIAN J. THOMAS Copyright 2012 by the Construction Financial Management Association. All rights reserved. This article first appeared in CFMA Building Profits. Reprinted with permission.

2 Cloud computing addresses many of the efficiencies contractors seek, including mobile accessibility, scalability, and more expansive Information Technology (IT) capabilities without massive outlays and larger long-term fixed costs. The collaborative work enabled by cloud computing is particularly useful for a contractor s accounting and financial reporting needs, allowing multiple vendors, subcontractors, and other stakeholders to be involved in these efforts. A concrete contractor in the Dallas-Fort Worth area uses a popular small business bookkeeping application hosted on the cloud. One of the company s two owners resides in San Antonio, TX, about 250 miles away, and spends 75% of his time overseeing company projects in that area. The company also works on longer-term projects in Huntsville, TX, which is approximately 170 miles away from both Dallas-Fort Worth and San Antonio. The contractor has six full-time administrative or management employees (including the two owners), and the number of foremen and crew members fluctuates depending on the volume of work. There is no IT specialist on the payroll. In terms of overall size and annual sales, the contractor is regarded as a small business. However, it must address the logistical concerns of employees who work hundreds of miles away from each other and ensure disparate individuals have access to accounting and financial information. While every business faces unique circumstances, this concrete contractor s use of the hosted bookkeeping software illustrates the benefits of utilizing cloud computing. Benefits of Cloud Computing Mobile Accessibility At any given time, a typical contractor has multiple projects underway, with each job incurring its own set of income and expense items. The ease with which cloud-based services may be accessed enables field staff to enter income and expense items as they re incurred into a common bookkeeping application, which bypasses the need to fax or information to the home office. In fact, it s increasingly common for field staff to place orders and receive inventory through smartphones or tablets. The increased popularity and use of laptops, smartphones, and tablets means that a contractor s IT network can now extend to virtually any location, whether it s a remote jobsite, hotel room, or office trailer. Because crucial information does not reside within an internal server, it can be accessed more easily from mobile end points. Scalability Cloud computing increases a contractor s flexibility to quickly scale its IT needs up or down based on business demand. Even extensive needs for additional cloud computing services at a new jobsite can often be arranged and implemented within a day. Since service fees are typically based on monthly usage, IT needs and costs can likewise be scaled back during slower business times. The first exhibit on the next page cites the top five motivators for adopting cloud technology based on responses from more than 4,000 IT professionals in 93 countries and 25 industries, with flexibility and scalability reported as the top motivator. Reduced Need for In-House IT Cloud computing can also reduce a contractor s need for inhouse IT acumen. A survey of more than 500 GCs, builders, remodelers, and specialty subcontractors with $2-51 million in annual revenues found that while construction and real estate companies seek greater efficiency, they do not have large in-house IT departments (as shown on the next page). Construction accounting processes have come to rely heavily on IT; greater functionality without the need for in-house expertise increases cloud computing s appeal. Lower Fixed Costs Regularly upgrading hardware or software equates to greater efficiencies and improves a contractor s ability to maintain CFMA BP July-August 2012

3 FOCUS Cloud Computing CONSTRUCTION ACCOUNTING accurate records and monitor financial performance. Since capitalizing on cloud computing only requires Internet access, fixed costs associated with software and hardware are eliminated. Collaboration Opportunities On any given construction project, how many entries must be made for material costs, per diem allowances, invoices, labor, etc.? How many people are involved in compiling that information? Cloud applications can be used to share project schedules, engineering plans, inventory totals, receipts, invoices, and other information among the project owner, GC, and subcontractors. The ease and accessibility of cloud-based applications and files can enable that information to be created once and then shared across organizations. In addition, subcontractors, suppliers, PMs, and other stakeholders can more easily collaborate in updating and reviewing financial information while work is underway. For example, billing can be handled more quickly for time and materials (T&M) jobs, and owner approvals of time for T&M jobs can be scanned into a database. Cloud-based services also aid in accumulating the approved field directives for the change order process. Cloud computing can also assist in documenting expense activity on a timely basis, thus providing PMs with updated job cost reports an important tool in monitoring project progress. (For more information on technologies that enable project collaboration, read Beyond Virtualization: Moving from Remote Access to True Collaboration by John B. Chaney in the July/August 2011 issue.) Consider & Address Disadvantages & Challenges Even though there are considerable potential advantages to cloud computing, there are also a number of concerns that should be addressed. For example, there may be integration challenges between multiple solutions or an increased dependency on vendors for support. It s also important to consider the process and factors involved in changing providers. In addition, there are different concerns associated with each cloud computing deployment method (public, private, hybrid): Cloud service provider (CSP) customers are often concerned about public cloud security, privacy, and capacity. While services provided exclusively for one customer in a private cloud alleviate many public cloud concerns, the cost can be a significant disadvantage. Hybrid cloud computing enables customers to enjoy advantages associated with both models. However, compatibility and integration issues between a private and public cloud must be addressed for the hybrid model to function effectively. What to Include in an SLA To help reduce these concerns, formally define a provider s services, and clarify a contractor s expectations, consider addressing the following in a Service Level Agreement (SLA): How will mobile device access be allocated to TOP 5 MOTIVATORS FOR ADOPTING CLOUD TECHNOLOGY 58% Flexibility and scalability 45% Reduced operating expenses 42% Efficiency 40% Reduced capital costs 35% Redundancy and disaster recovery 43% of construction or real estate companies in the U.S. have one IT staff person 36% have no in-house IT staff 57% of survey respondents believe efficiency is the most important action to take in % of respondents assigned high importance to mobile technology TECHNOLOGY TRENDS IN THE CONSTRUCTION INDUSTRY Source: 2011 IBM Tech Trends Report, published by IBM s developerworks. Source: Opportunity 2012: Construction Industry Technology Trends, published by Sage Construction and Real Estate. July-August 2012 CFMA BP

4 disparate stakeholders, and will any difficulties arise when those individuals seek to work in a collaborative manner? If an accounting application is provided in SaaS format, does the software include any administrative settings that define what data and functions may be accessed by different parties (e.g., subcontractors, customers, lenders, or other parties)? How will collaborative files be transferred (e.g., Excel, Word, or PDF)? LEVELS OF CLOUD COMPUTING Cloud computing services are offered in three general levels: Software as a service (SaaS), platform as a service (PaaS), and infrastructure as a service (IaaS). The particular level a contractor might choose depends on its specific circumstances and needs. SaaS SaaS is an application fully hosted by a software company or CSP that customers access via an Internet connection. Software use is typically licensed on a monthly subscription basis, and some contract provisions can be based on overall usage or number of users. The customer does not need to perform any installations, troubleshoot any difficulties, or download any upgrades or enhancements. However, there are limited options for customizing the software to fit specific company needs or preferences. PaaS PaaS enables users to design the applications that are hosted by a CSP. This level of cloud computing provides the benefits of customized software without having to maintain the supporting infrastructure. IaaS IaaS represents the most comprehensive level of cloud computing. In addition to hosting applications and software platforms, available services include virtual servers and immense data storage capacity. What is the common cutoff date for data input and reporting? Is there coordination and consistent practices among all data processors? Are there any compliance or regulatory issues (e.g., Sarbanes-Oxley compliance for public companies or data discovery requests for litigation matters)? Has the company s reliance on Internet connectivity been considered? Have record retention concerns been addressed and management terms defined? How will an external auditor or tax professional find necessary financial information? If the accumulated data is migrated to another service provider, who owns it? Do provisions exist for defining how such migrations can occur? Attain Proper Assurance Contractors that wish to attain proper assurance for cloud computing functions related to construction accounting would be interested in the AICPA s Service Organization Control (SOC) reports that accompany the use of Statement on Standards for Attestation Engagements (SSAE) No. 16, Reporting on Controls at a Service Organization. 1 The SOC 1 report is designed for providers that offer services related to financial reporting that rely on IT. This report encompasses the objectives of SSAE No. 16. The SOC 2 and SOC 3 reports are based on the following AICPA Trust Services Principles & Criteria: Security Availability Processing integrity Confidentiality Privacy The SOC 2 report includes a description of the service organization s system, a CPA s opinion on the fairness of presentation of the description, and suitability of the system s design. The report also includes tests performed by the CPA to gauge the effectiveness of those controls, as well as the results from those tests. The SOC 2 report can include any combination of the Trust Services Principles & Criteria, which enables the service CFMA BP July-August 2012

5 FOCUS Cloud Computing CONSTRUCTION ACCOUNTING organization to focus on issues most relevant to its operations and customers. The SOC 3 report is a general use report that is more suited for marketing purposes. It includes an auditor s report on whether the system achieved the trust services criteria, but does not include test results. Capitalizing on Benefits Requires Careful Evaluation When considering a move to the cloud, it is critical that contractors evaluate what controls the vendor has in place to monitor various IT considerations, including security, data integrity, and availability. Contractors also need to consider what audits the CSP undergoes to ensure that its operations mitigate risks, and how various compliance concerns would be met. By carefully evaluating such considerations, a contractor can benefit from moving appropriate IT operations to a cloud environment. n THE LIFELINE FOR CLOUD COMPUTING: INTERNET CONNECTIVITY Cloud computing relies on Internet connectivity, which can be disrupted on either the user or CSP s end by such factors as bad weather, technical issues, or a severed transmission line. Also, a jobsite s location may make connectivity an especially challenging concern. In response, contractors must evaluate their dependency on the computing assets they would consider moving to the cloud. Below are several actions contractors can take to manage the lost Internet connectivity risk for critical company assets (i.e., those where even minimal disruption cannot be tolerated). Endnote: 1. The development of SSAE No. 16 represents a larger effort to converge U.S. and international accounting standards. For more on this topic, read Understanding the Information System Audit Process by Victor M. Marshall and Scott M. Lewis in the March/ April 2012 issue. BRIAN J. THOMAS, CISA, CISSP, is a Partner in Advisory Services for Weaver in its Houston, TX office. He manages teams that deliver IT-focused solutions such as SOC reporting (SAS 70, SSAE 16, etc.), system integration, information security, SOX assistance, IT audits, and IT project management. He has more than 14 years of experience in consulting and managing teams, including nearly nine years of Big Four firm experience. Brian holds a BS and Masters in Civil Engineering from the University of Texas at Austin. He is a member of numerous industry associations, including AICPA Cloud Computing and SOC Reporting Task Forces. Phone: Website: Ensure that redundant connectivity capabilities (i.e., multiple Internet service providers) exist for the home office and field offices. Perform due diligence on any CSP before utilizing that vendor s services. Ask the CSP how Internet connectivity risks are addressed and what redundancies are in place to prevent connectivity losses. Investigate whether the CSP has ever encountered connectivity issues. If such issues have occurred, ask how those difficulties were resolved and how long it took to restore service. Potential customers can validate responses through Internet searches, as lost connectivity by notable CSPs typically receives widespread exposure. Consider potential regulatory concerns regarding financial reporting due to a CSP s physical facility in another state or country. July-August 2012 CFMA BP

TECH INSIGHTS TRUST AND TRANSPARENCY IN A CLOUDY WORLD. IT advisory services

TECH INSIGHTS TRUST AND TRANSPARENCY IN A CLOUDY WORLD. IT advisory services TECH INSIGHTS IT advisory services TRUST AND TRANSPARENCY IN A CLOUDY WORLD Service Organization Controls (SOC) Reporting for Financial and Data Security In a world of cloud computing and business process

More information

Cloud Computing; What is it, How long has it been here, and Where is it going?

Cloud Computing; What is it, How long has it been here, and Where is it going? Cloud Computing; What is it, How long has it been here, and Where is it going? David Losacco, CPA, CIA, CISA Principal January 10, 2013 Agenda The Cloud WHAT IS THE CLOUD? How long has it been here? Where

More information

OFFICE OF AUDITS & ADVISORY SERVICES CLOUD COMPUTING AUDIT FINAL REPORT

OFFICE OF AUDITS & ADVISORY SERVICES CLOUD COMPUTING AUDIT FINAL REPORT County of San Diego Auditor and Controller OFFICE OF AUDITS & ADVISORY SERVICES CLOUD COMPUTING AUDIT FINAL REPORT Chief of Audits: Juan R. Perez Audit Manager: Lynne Prizzia, CISA, CRISC Senior Auditor:

More information

Understanding SOC Reports for Effective Vendor Management. Jason T. Clinton January 26, 2016

Understanding SOC Reports for Effective Vendor Management. Jason T. Clinton January 26, 2016 Understanding SOC Reports for Effective Vendor Management Jason T. Clinton January 26, 2016 MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT FIRMS 2012 Wolf & Company, P.C. Before we

More information

Cloud Computing An Auditor s Perspective

Cloud Computing An Auditor s Perspective Cloud Computing An Auditor s Perspective Sailesh Gadia, CPA, CISA, CIPP sgadia@kpmg.com December 9, 2010 Discussion Agenda Introduction to cloud computing Types of cloud services Benefits, challenges,

More information

Keeping up with the World of Cloud Computing: What Should Internal Audit be Thinking About?

Keeping up with the World of Cloud Computing: What Should Internal Audit be Thinking About? Keeping up with the World of Cloud Computing: What Should Internal Audit be Thinking About? IIA San Francisco Chapter October 11, 2011 Agenda Introductions Cloud computing overview Risks and audit strategies

More information

SSAE 16 for Transportation & Logistics Companies. Chris Kradjan Kim Koch

SSAE 16 for Transportation & Logistics Companies. Chris Kradjan Kim Koch SSAE 16 for Transportation & Logistics Companies Chris Kradjan Kim Koch 1 The material appearing in this presentation is for informational purposes only and should not be construed as advice of any kind,

More information

The Elephant in the Room: What s the Buzz Around Cloud Computing?

The Elephant in the Room: What s the Buzz Around Cloud Computing? The Elephant in the Room: What s the Buzz Around Cloud Computing? Warren W. Stippich, Jr. Partner and National Governance, Risk and Compliance Solution Leader Business Advisory Services Grant Thornton

More information

IT Insights. Managing Third Party Technology Risk

IT Insights. Managing Third Party Technology Risk IT Insights Managing Third Party Technology Risk According to a recent study by the Institute of Internal Auditors, more than 65 percent of organizations rely heavily on third parties, yet most allocate

More information

HARNESSING THE POWER OF THE CLOUD

HARNESSING THE POWER OF THE CLOUD HARNESSING THE POWER OF THE CLOUD Demystifying Cloud Computing Everyone is talking about the cloud nowadays. What does it really means? Indeed, cloud computing is the current stage in the Internet evolution.

More information

Cloud computing. Advantages and disadvantages

Cloud computing. Advantages and disadvantages Cloud computing Advantages and disadvantages CPA Australia Ltd ( CPA Australia ) is one of the world s largest accounting bodies representing more than 139,000 members of the financial, accounting and

More information

WHY CLOUD COMPUTING MAKES SENSE FOR NONPROFITS

WHY CLOUD COMPUTING MAKES SENSE FOR NONPROFITS WHY CLOUD COMPUTING MAKES SENSE FOR NONPROFITS Nonprofits are experiencing increased pressure, oversight, and demand for transparency from all sides. Whether the focus is government compliance, competition

More information

35 Questions Every CFO Needs to Ask About ERP Software In the Cloud

35 Questions Every CFO Needs to Ask About ERP Software In the Cloud Brought to you by: 35 Questions Every CFO Needs to Ask About ERP Software In the Cloud The ERP Software Blog is proud to bring you The ERP PANEL PAPERS A straightforward series of white papers from a nationwide

More information

AHLA. JJ. Keeping Your Cloud Services Provider from Raining on Your Parade. Jean Hess Manager HORNE LLP Ridgeland, MS

AHLA. JJ. Keeping Your Cloud Services Provider from Raining on Your Parade. Jean Hess Manager HORNE LLP Ridgeland, MS AHLA JJ. Keeping Your Cloud Services Provider from Raining on Your Parade Jean Hess Manager HORNE LLP Ridgeland, MS Melissa Markey Hall Render Killian Heath & Lyman PC Troy, MI Physicians and Hospitals

More information

Cloud Enabled Business Transformation. Carl Rönnerstam March 14 th 2012

Cloud Enabled Business Transformation. Carl Rönnerstam March 14 th 2012 Cloud Enabled Business Transformation Carl Rönnerstam March 14 th 2012 Carl Rönnerstam Head of IT Strategy & Transformation KPMG Advisory Sweden Management Consulting Telephone +46 766 312 590 carl.ronnerstam@kpmg.se

More information

Trends in Cloud Computing in Higher Education

Trends in Cloud Computing in Higher Education An white paper sponsored by ViON Trends in Cloud Computing in Higher Education Colleges and universities are making their way into cloud computing unevenly, but with a sense of inevitability. How are higher

More information

SECURITY AND EXTERNAL SERVICE PROVIDERS

SECURITY AND EXTERNAL SERVICE PROVIDERS SECURITY AND EXTERNAL SERVICE PROVIDERS How to ensure regulatory compliance and manage risks with Service Organization Control (SOC) Reports Jorge Rey, CISA, CISM, CGEIT Director, Information Security

More information

SECURITY RISK MANAGEMENT

SECURITY RISK MANAGEMENT SECURITY RISK MANAGEMENT ISACA Atlanta Chapter, Geek Week August 20, 2013 Scott Ritchie, Manager, HA&W Information Assurance Services Scott Ritchie CISSP, CISA, PCI QSA, ISO 27001 Auditor Manager, HA&W

More information

IT Cloud / Data Security Vendor Risk Management Associated with Data Security. September 9, 2014

IT Cloud / Data Security Vendor Risk Management Associated with Data Security. September 9, 2014 IT Cloud / Data Security Vendor Risk Management Associated with Data Security September 9, 2014 Speakers Brian Thomas, CISA, CISSP In charge of Weaver s IT Advisory Services, broad focus on IT risk, security

More information

Daren Kinser Auditor, UCSD Jennifer McDonald Auditor, UCSD

Daren Kinser Auditor, UCSD Jennifer McDonald Auditor, UCSD Daren Kinser Auditor, UCSD Jennifer McDonald Auditor, UCSD Agenda Cloud Computing Technical Overview Cloud Related Applications Identified Risks Assessment Criteria Cloud Computing What Is It? National

More information

Why You Should Consider Cloud- Based Email Archiving. A whitepaper by The Radicati Group, Inc.

Why You Should Consider Cloud- Based Email Archiving. A whitepaper by The Radicati Group, Inc. . The Radicati Group, Inc. 1900 Embarcadero Road, Suite 206 Palo Alto, CA 94303 Phone 650-322-8059 Fax 650-322-8061 http://www.radicati.com THE RADICATI GROUP, INC. Why You Should Consider Cloud- Based

More information

Electronic Records Storage Options and Overview

Electronic Records Storage Options and Overview Electronic Records Storage Options and Overview www.archives.nysed.gov Objectives Understand the options for electronic records storage, including cloud-based storage Evaluate the options best suited for

More information

SOC on Amazon Web Services (AWS) What You Need To Know Understanding the regulatory roadmap for SOC on AWS

SOC on Amazon Web Services (AWS) What You Need To Know Understanding the regulatory roadmap for SOC on AWS SOC on Amazon Web Services (AWS) What You Need To Know Understanding the regulatory roadmap for SOC on AWS Jeff Cook November 2015 Summary Service Organization Control (SOC) reports (formerly SAS 70 or

More information

Bringing the Cloud into Focus:

Bringing the Cloud into Focus: Bringing the Cloud into Focus: Things to Consider When Selecting Cloud-Based Museum Collections Management Software Presented by www.historyassociates.com Thinking About a Cloud-Based CMS? In addition

More information

GETTING THE MOST FROM THE CLOUD. A White Paper presented by

GETTING THE MOST FROM THE CLOUD. A White Paper presented by GETTING THE MOST FROM THE CLOUD A White Paper presented by Why Move to the Cloud? CLOUD COMPUTING the latest evolution of IT services delivery is a scenario under which common business applications are

More information

Desktop Solutions SolutioWhitepaper

Desktop Solutions SolutioWhitepaper Author: Mike Herrmann With organizations looking for new ways to cut costs and increase productivity, the use of cloud computing has grown. The most common form of cloud computing is for vendors making

More information

A Vendor s Journey to SaaS & the Cloud

A Vendor s Journey to SaaS & the Cloud A Vendor s Journey to SaaS & the Cloud Mark Sherry Partner Marval North America ITIL Expert ISO 20000 Consultant MBA, MA, BComm 25+ ITIL implementations Trained Service Managers Globally 10 Years in Industry

More information

Things You Need to Know About Cloud Backup

Things You Need to Know About Cloud Backup Things You Need to Know About Cloud Backup Over the last decade, cloud backup, recovery and restore (BURR) options have emerged as a secure, cost-effective and reliable method of safeguarding the increasing

More information

Why Migrate to the Cloud. ABSS Solutions, Inc. 2014

Why Migrate to the Cloud. ABSS Solutions, Inc. 2014 Why Migrate to the Cloud ABSS Solutions, Inc. 2014 ASI Cloud Services Information Systems Basics Cloud Fundamentals Cloud Options Why Move to the Cloud Our Service Providers Our Process Information System

More information

Why Cloud CompuTing ThreaTens midsized enterprises and WhaT To do about it

Why Cloud CompuTing ThreaTens midsized enterprises and WhaT To do about it The Cloud Threat Why Cloud CompuTing ThreaTens midsized enterprises and WhaT To do about it This white paper outlines the concerns that often prevent midsized enterprises from taking advantage of the Cloud.

More information

CLOUD MIGRATION. Celina Alexandre M6807

CLOUD MIGRATION. Celina Alexandre M6807 CLOUD MIGRATION M6807 S Content 1. Introduction 2. Methodology 3. Requirements Definition Phase 3.1. Strategy 3.2. Knowledge 06/05/15 2 Content 4. Analysis Phase 4.1. Aplications and Systems 4.2. Development

More information

IBM Cognos TM1 on Cloud Solution scalability with rapid time to value

IBM Cognos TM1 on Cloud Solution scalability with rapid time to value IBM Solution scalability with rapid time to value Cloud-based deployment for full performance management functionality Highlights Reduced IT overhead and increased utilization rates with less hardware.

More information

Cloud Computing. What is Cloud Computing?

Cloud Computing. What is Cloud Computing? Cloud Computing What is Cloud Computing? Cloud computing is where the organization outsources data processing to computers owned by the vendor. Primarily the vendor hosts the equipment while the audited

More information

Introduction to Cloud Computing

Introduction to Cloud Computing Small Logo Introduction to Cloud Computing Executive Summary A common understanding of cloud computing is continuously evolving, and the terminology and concepts used to define it often need clarifying.

More information

Refresher on cloud computing

Refresher on cloud computing Refresher on cloud computing Cloud computing is a form of outsourcing where the organization outsources data processing to computers owned by the vendor. Outsourcing may also include utilizing the vendor

More information

2014 HIMSS Analytics Cloud Survey

2014 HIMSS Analytics Cloud Survey 2014 HIMSS Analytics Cloud Survey June 2014 2 Introduction Cloud services have been touted as a viable approach to reduce operating expenses for healthcare organizations. Yet, engage in any conversation

More information

Cloud Computing Readiness - Background

Cloud Computing Readiness - Background IT Best Practices Audit Cloud Computing Readiness - Background Cloud based offerings are maturing and finally taking off after a long period (e.g. Software as a Service offerings have been available for

More information

SERVICE ORGANIZATION CONTROL REPORTS SM. Formerly SAS 70 Reports

SERVICE ORGANIZATION CONTROL REPORTS SM. Formerly SAS 70 Reports SERVICE ORGANIZATION CONTROL REPORTS SM Formerly SAS 70 Reports SAS No. 70, Service Organizations Standard for reporting on a service organization s controls affecting user entities financial statements

More information

Commercial Software Licensing

Commercial Software Licensing Commercial Software Licensing CHAPTER 12: Prepared by DoD ESI January 2013 Chapter Overview Most software licenses today are either perpetual or subscription. Perpetual licenses involve software possession

More information

Cloud Computing demystified! ISACA-IIA Joint Meeting Dec 9, 2014 By: Juman Doleh-Alomary Office of Internal Audit jdoleh@wayne.edu

Cloud Computing demystified! ISACA-IIA Joint Meeting Dec 9, 2014 By: Juman Doleh-Alomary Office of Internal Audit jdoleh@wayne.edu Cloud Computing demystified! ISACA-IIA Joint Meeting Dec 9, 2014 By: Juman Doleh-Alomary Office of Internal Audit jdoleh@wayne.edu 2 If cloud computing is so simple, then what s the big deal? What is the

More information

10 Considerations for a Cloud Procurement. Anthony Kelly Erick Trombley David DeBrandt Carina Veksler January 2015

10 Considerations for a Cloud Procurement. Anthony Kelly Erick Trombley David DeBrandt Carina Veksler January 2015 10 Considerations for a Cloud Procurement Anthony Kelly Erick Trombley David DeBrandt Carina Veksler January 2015 www.lbmctech.com info@lbmctech.com Purpose: Cloud computing provides public sector organizations

More information

Joining The Cloud Revolution

Joining The Cloud Revolution Joining The Cloud Revolution Table of Contents 1. What is Cloud Computing? a. Technology overview: Joining the b. Different approaches to the cloud i. Software as a Service ii. Platform as a Service iii.

More information

Data Protection Act 1998. Guidance on the use of cloud computing

Data Protection Act 1998. Guidance on the use of cloud computing Data Protection Act 1998 Guidance on the use of cloud computing Contents Overview... 2 Introduction... 2 What is cloud computing?... 3 Definitions... 3 Deployment models... 4 Service models... 5 Layered

More information

WELCOME TO SECURE360 2013

WELCOME TO SECURE360 2013 WELCOME TO SECURE360 2013 Don t forget to pick up your Certificate of Attendance at the end of each day. Please complete the Session Survey front and back, and leave it on your seat. Are you tweeting?

More information

CLOUD FAX SOLUTIONS BUYER S GUIDE

CLOUD FAX SOLUTIONS BUYER S GUIDE CLOUD FAX SOLUTIONS BUYER S GUIDE TABLE OF CONTENTS INTRODUCTION 1 2 3 4 Define Your Needs Business Goals Requirements Compare Solutions Select Top Solutions Talk to References Do Demos/Trials Make Your

More information

White Paper. How Construction Companies Benefit From Using The Cloud. 2015 Cloud9 Real Time (888) 869-0076 www.cloud9realtime.com

White Paper. How Construction Companies Benefit From Using The Cloud. 2015 Cloud9 Real Time (888) 869-0076 www.cloud9realtime.com White Paper How Construction Companies Benefit From Using The Cloud How Construction Companies Benefit From Using The Cloud 3 Summary Why should construction companies utilize the Cloud? Whether you own

More information

Baker Tilly refers to Baker Tilly Virchow Krause, LLP, an independently owned and managed member of Baker Tilly International. Understanding SOC 3

Baker Tilly refers to Baker Tilly Virchow Krause, LLP, an independently owned and managed member of Baker Tilly International. Understanding SOC 3 Baker Tilly refers to Baker Tilly Virchow Krause, LLP, an independently owned and managed member of Baker Tilly International. Understanding SOC 3 Agenda 1) A brief perspective on where SOC 3 originated

More information

Cloud Computing Discussion K P M G L L P

Cloud Computing Discussion K P M G L L P Cloud Computing Discussion K P M G L L P 2/12/2012 1 Presenters 2 Presenter Information RICHARD ARCHER Rich is a partner in KPMG s Advisory Services Practice based in Pittsburgh. Rich has assisted clients

More information

CONSIDERATIONS BEFORE MOVING TO THE CLOUD

CONSIDERATIONS BEFORE MOVING TO THE CLOUD CONSIDERATIONS BEFORE MOVING TO THE CLOUD What Management Needs to Know Part I By Debbie C. Sasso Principal When talking technology today, it s very rare that the word Cloud doesn t come up. The benefits

More information

3 rd Party Vendor Risk Management

3 rd Party Vendor Risk Management 3 rd Party Vendor Risk Management Session 402 Tuesday, June 9, 2015 (11 to 12pm) Session Objectives The need for enhanced reporting on vendor risk management Current outsourcing environment Key risks faced

More information

Is Cloud Accounting Right for Your Business? An Educational Report

Is Cloud Accounting Right for Your Business? An Educational Report Is Cloud Accounting Right for Your Business? An Educational Report One of the most exciting changes in the accounting industry is cloud accounting. The concept is easy to grasp: cloud accounting simply

More information

Cloud Security Panel: Real World GRC Experiences. ISACA Atlanta s 2013 Annual Geek Week

Cloud Security Panel: Real World GRC Experiences. ISACA Atlanta s 2013 Annual Geek Week Cloud Security Panel: Real World GRC Experiences ISACA Atlanta s 2013 Annual Geek Week Agenda Introductions Recap: Overview of Cloud Computing and Why Auditors Should Care Reference Materials Panel/Questions

More information

What Every User Needs To Know Before Moving To The Cloud. LawyerDoneDeal Corp.

What Every User Needs To Know Before Moving To The Cloud. LawyerDoneDeal Corp. What Every User Needs To Know Before Moving To The Cloud LawyerDoneDeal Corp. What Every User Needs To Know Before Moving To The Cloud 1 What is meant by Cloud Computing, or Going To The Cloud? A model

More information

Managing Cloud Computing Risk

Managing Cloud Computing Risk Managing Cloud Computing Risk Presented By: Dan Desko; Manager, Internal IT Audit & Risk Advisory Services Schneider Downs & Co. Inc. ddesko@schneiderdowns.com Learning Objectives Understand how to identify

More information

Cloud Computing Risk and Rewards

Cloud Computing Risk and Rewards Cloud Computing Risk and Rewards John Lazarine Vice President and Chief Audit Executive Mark Salamasick Director of Center for Internal Auditing For Dallas CPA Society Convergence 2013 May 8, 2013 John

More information

Time to Value: Successful Cloud Software Implementation

Time to Value: Successful Cloud Software Implementation Time to Value: Successful Cloud Software Implementation Cloud & Data Security 2015 Client Conference About the Presenter Scott Schimberg, CPA, CMA Partner, Consulting, Armanino Scott became a Certified

More information

SOC Readiness Assessments. SOC Report - Type 1. SOC Report - Type 2. Building Trust and Confidence in Third-Party Relationships

SOC Readiness Assessments. SOC Report - Type 1. SOC Report - Type 2. Building Trust and Confidence in Third-Party Relationships Building Trust and Confidence in Third-Party Relationships Today s businesses rely heavily on outsourcing certain business tasks or functions to service organizations, even those that are core to their

More information

SSAE 16 Everything You Wanted To Know But Are Afraid To Ask. Kurt Hagerman CISA, CISSP, QSA Managing Director, Coalfire December 8, 2011

SSAE 16 Everything You Wanted To Know But Are Afraid To Ask. Kurt Hagerman CISA, CISSP, QSA Managing Director, Coalfire December 8, 2011 SSAE 16 Everything You Wanted To Know But Are Afraid To Ask Kurt Hagerman CISA, CISSP, QSA Managing Director, Coalfire December 8, 2011 1 Agenda SAS 70 Misunderstood and Overused o Why the change? SSAE

More information

SaaS or On-Premise Monitoring: 9 Reasons SaaS Makes More Sense

SaaS or On-Premise Monitoring: 9 Reasons SaaS Makes More Sense SaaS or On-Premise Monitoring: 9 Reasons SaaS Makes More Sense You know that cloud-based services provide advantages, including: Low upfront costs Fast deployment Simplified administration We know that

More information

Cloud Security and Managing Use Risks

Cloud Security and Managing Use Risks Carl F. Allen, CISM, CRISC, MBA Director, Information Systems Security Intermountain Healthcare Regulatory Compliance External Audit Legal and ediscovery Information Security Architecture Models Access

More information

Get Significant Application Quality Improvement without Major Investment Performance driven. Quality assured.

Get Significant Application Quality Improvement without Major Investment Performance driven. Quality assured. Testing Platform-as-aService Get Significant Application Quality Improvement without Major Investment Performance driven. Quality assured. TPaaS providing testing on demand, using the Capgemini Cloud Application

More information

Private & Hybrid Cloud: Risk, Security and Audit. Scott Lowry, Hassan Javed VMware, Inc. March 2012

Private & Hybrid Cloud: Risk, Security and Audit. Scott Lowry, Hassan Javed VMware, Inc. March 2012 Private & Hybrid Cloud: Risk, Security and Audit Scott Lowry, Hassan Javed VMware, Inc. March 2012 Private and Hybrid Cloud - Risk, Security and Audit Objectives: Explain the technology and benefits behind

More information

Risky Business. Is Your Cybersecurity in Cruise Control? ISACA Austin Chapter Meeting May 5, 2015

Risky Business. Is Your Cybersecurity in Cruise Control? ISACA Austin Chapter Meeting May 5, 2015 Risky Business Is Your Cybersecurity in Cruise Control? ISACA Austin Chapter Meeting May 5, 2015 What We ll Cover About Me Background The threat Risks to your organization What your organization can/should

More information

White Paper on CLOUD COMPUTING

White Paper on CLOUD COMPUTING White Paper on CLOUD COMPUTING INDEX 1. Introduction 2. Features of Cloud Computing 3. Benefits of Cloud computing 4. Service models of Cloud Computing 5. Deployment models of Cloud Computing 6. Examples

More information

White Paper. What the ideal cloud-based web security service should provide. the tools and services to look for

White Paper. What the ideal cloud-based web security service should provide. the tools and services to look for White Paper What the ideal cloud-based web security service should provide A White Paper by Bloor Research Author : Fran Howarth Publish date : February 2010 The components required of an effective web

More information

Strategic Compliance & Securing the Cloud. Annalea Sharack-Ilg, CISSP, AMBCI Technical Director of Information Security

Strategic Compliance & Securing the Cloud. Annalea Sharack-Ilg, CISSP, AMBCI Technical Director of Information Security Strategic Compliance & Securing the Cloud Annalea Sharack-Ilg, CISSP, AMBCI Technical Director of Information Security Complexity and Challenges 2 Complexity and Challenges Compliance Regulatory entities

More information

How cloud computing can transform your business landscape.

How cloud computing can transform your business landscape. How cloud computing can transform your business landscape. This whitepaper will help you understand the ways cloud computing can benefit your business. Introduction It seems like everyone is talking about

More information

The Keys to the Cloud: The Essentials of Cloud Contracting

The Keys to the Cloud: The Essentials of Cloud Contracting The Keys to the Cloud: The Essentials of Cloud Contracting September 30, 2014 Bert Kaminski Assistant General Counsel, Oracle North America Ken Adler Partner, Loeb & Loeb LLP Akiba Stern Partner, Loeb

More information

EMAIL ARCHIVING SERVICES SERVICE DEFINITION

EMAIL ARCHIVING SERVICES SERVICE DEFINITION Complete IT Support for Business Westgate IT Email Archiving Services: Service Definition Service Name Email Archiving Services Overview of Service Westgate IT s Email Archiving Services provide a reliable

More information

What you need to know about cloud backup: your guide to cost, security, and flexibility. 8 common questions answered

What you need to know about cloud backup: your guide to cost, security, and flexibility. 8 common questions answered What you need to know about cloud backup: your guide to cost, security, and flexibility. 8 common questions answered Over the last decade, cloud backup, recovery and restore (BURR) options have emerged

More information

Windows Server 2003. Your data will be non-compliant & at risk on

Windows Server 2003. Your data will be non-compliant & at risk on Your data will be non-compliant & at risk on Windows Server 2003. On July 14 th 2015, Microsoft will cease its support (including automatic bug fixes, updates and online technical assistance) for Windows

More information

How cloud computing can transform your business landscape

How cloud computing can transform your business landscape How cloud computing can transform your business landscape Introduction It seems like everyone is talking about the cloud. Cloud computing and cloud services are the new buzz words for what s really a not

More information

Cloud Service Rollout. Chapter 9

Cloud Service Rollout. Chapter 9 Cloud Service Rollout Chapter 9 Cloud Service Topics Cloud service rollout plans vary depending on the type of cloud service SaaS, PaaS, or IaaS and the vendor. Unit Topics Identifying vendor roles and

More information

Email Archiving Services

Email Archiving Services Email Archiving Services A reliable offsite and secure storage facility for your emails G-Cloud 5 Service Definition CONTENTS Overview of Service... 2 Effortless Protection... 3 Optional legacy Email Import...

More information

TECHNOLOGY GUIDE THREE. Emerging Types of Enterprise Computing

TECHNOLOGY GUIDE THREE. Emerging Types of Enterprise Computing TECHNOLOGY GUIDE THREE Emerging Types of Enterprise Computing TECHNOLOGY GU IDE OUTLINE TG3.1 Introduction TG3.2 Server Farms TG3.3 Virtualization TG3.4 Grid Computing TG3.5 Utility Computing TG3.6 Cloud

More information

Leveraging the Cloud for your Business

Leveraging the Cloud for your Business Leveraging the Cloud for your Business Save money and time by moving to the cloud Learn how Moving to the Cloud 3 from small and mid-sized businesses (SMBs) to Enterprise Companies. What problems can cloud

More information

Cloud Computing: Background, Risks and Audit Recommendations

Cloud Computing: Background, Risks and Audit Recommendations Cloud Computing: Background, Risks and Audit Recommendations October 30, 2014 Table of Contents Cloud Computing: Overview 3 Multiple Models of Cloud Computing 11 Deployment Models 16 Considerations For

More information

The Cloud is Not Enough Why Hybrid Infrastructure is Shaping the Future of Cloud Computing

The Cloud is Not Enough Why Hybrid Infrastructure is Shaping the Future of Cloud Computing Your Platform of Choice The Cloud is Not Enough Why Hybrid Infrastructure is Shaping the Future of Cloud Computing Mark Cravotta EVP Sales and Service SingleHop LLC Talk About Confusing? Where do I start?

More information

SAS No. 70, Service Organizations

SAS No. 70, Service Organizations SAS No. 70, Service Organizations A standard for reporting on a service organization s controls affecting user entities' financial statements. Only for use by service organization management, existing

More information

Introduction to Cloud Computing

Introduction to Cloud Computing 1 Introduction to Cloud Computing CERTIFICATION OBJECTIVES 1.01 Cloud Computing: Common Terms and Definitions 1.02 Cloud Computing and Virtualization 1.03 Early Examples of Cloud Computing 1.04 Cloud Computing

More information

Wednesday, January 16, 2013

Wednesday, January 16, 2013 Attorney Advertising Prior results do not guarantee a similar outcome Models used are not clients but may be representative of clients 321 N. Clark Street, Suite 2800, Chicago, IL 60654 312.832.4500 Wednesday,

More information

Validating Enterprise Systems: A Practical Guide

Validating Enterprise Systems: A Practical Guide Table of Contents Validating Enterprise Systems: A Practical Guide Foreword 1 Introduction The Need for Guidance on Compliant Enterprise Systems What is an Enterprise System The Need to Validate Enterprise

More information

Cloud Security Trust Cisco to Protect Your Data

Cloud Security Trust Cisco to Protect Your Data Trust Cisco to Protect Your Data As cloud adoption accelerates, organizations are increasingly placing their trust in third-party cloud service providers (CSPs). But can you fully trust your most sensitive

More information

Module 1: Facilitated e-learning

Module 1: Facilitated e-learning Module 1: Facilitated e-learning CHAPTER 3: OVERVIEW OF CLOUD COMPUTING AND MOBILE CLOUDING: CHALLENGES AND OPPORTUNITIES FOR CAs... 3 PART 1: CLOUD AND MOBILE COMPUTING... 3 Learning Objectives... 3 1.1

More information

EXIN Cloud Computing Foundation

EXIN Cloud Computing Foundation Sample Questions EXIN Cloud Computing Foundation Edition April 2013 Copyright 2013 EXIN All rights reserved. No part of this publication may be published, reproduced, copied or stored in a data processing

More information

Understanding Vendor Risk And Analyzing the SSAE No. 16

Understanding Vendor Risk And Analyzing the SSAE No. 16 Understanding Vendor Risk And Analyzing the SSAE No. 16 Accelerate your Credit Union s Performance June 19, 2014 AUSTIN, TEXAS www.cuaccelerator.com Agenda Vendor Management Key Outsourcing Risk Areas

More information

Why SAAS makes sense: The benefits of Cloud Computing for Email Archiving

Why SAAS makes sense: The benefits of Cloud Computing for Email Archiving Why SAAS makes sense: The benefits of Cloud Computing for Email Archiving Confidentiality This document contains confidential material that is proprietary to Gradian Systems Ltd. The material, ideas, and

More information

Sage ERP I White Paper. ERP and the Cloud: What You Need to Know

Sage ERP I White Paper. ERP and the Cloud: What You Need to Know I White Paper ERP and the Cloud: What You Need to Know Table of Contents Executive Summary... 3 Increased Interest in Cloud-Based ERP and SaaS Implementations... 3 What is Cloud/SaaS ERP?... 3 Why Interest

More information

Leveraging the Cloud for Your Business

Leveraging the Cloud for Your Business Leveraging the Cloud for Your Business by CornerStone Telephone Company 2 Third Street Troy, NY 12180 As consumers, we enjoy the benefits of cloud services from companies like Amazon, Google, Apple and

More information

WHITE PAPER. 5 Ways Your Organization is Missing Out on Massive Opportunities By Not Using Cloud Software

WHITE PAPER. 5 Ways Your Organization is Missing Out on Massive Opportunities By Not Using Cloud Software WHITE PAPER 5 Ways Your Organization is Missing Out on Massive Opportunities By Not Using Cloud Software Cloud software allows your organization to focus on its strengths and outsource tough data storage

More information

What You Need to Know About Cloud Backup: Your Guide to Cost, Security, and Flexibility

What You Need to Know About Cloud Backup: Your Guide to Cost, Security, and Flexibility Your Guide to Cost, Security, and Flexibility What You Need to Know About Cloud Backup: Your Guide to Cost, Security, and Flexibility 10 common questions answered Over the last decade, cloud backup, recovery

More information

Cloud Computing. Chapter 1 Introducing Cloud Computing

Cloud Computing. Chapter 1 Introducing Cloud Computing Cloud Computing Chapter 1 Introducing Cloud Computing Learning Objectives Understand the abstract nature of cloud computing. Describe evolutionary factors of computing that led to the cloud. Describe virtualization

More information

Developing SAP Enterprise Cloud Computing Strategy

Developing SAP Enterprise Cloud Computing Strategy White Paper WFT Cloud Technology SAP Cloud Integration Service Provider Developing SAP Enterprise Cloud Computing Strategy SAP Cloud Computing is a significant IT paradigm change with the potential to

More information

Contact Centers in the Cloud: A Better Way to Source

Contact Centers in the Cloud: A Better Way to Source Contact Centers in the Cloud: A Better Way to Source By Irwin Lazar Vice President and Service Director, Nemertes Research Executive Summary Contact Center Software as a Service (CCSaaS) solutions provide

More information

WHY YOU SHOULD CONSIDER CLOUD BASED EMAIL ARCHIVING.

WHY YOU SHOULD CONSIDER CLOUD BASED EMAIL ARCHIVING. WHY YOU SHOULD CONSIDER CLOUD BASED EMAIL ARCHIVING. INTRODUCTION A vast majority of information today is being exchanged via email. In 2011, the average corporate user will send and receive about 112

More information

Requirements Checklist for Choosing a Cloud Backup and Recovery Service Provider

Requirements Checklist for Choosing a Cloud Backup and Recovery Service Provider Whitepaper: Requirements Checklist for Choosing a Cloud Backup and Recovery Service Provider WHITEPAPER Requirements Checklist for Choosing a Cloud Backup and Recovery Service Provider Requirements Checklist

More information

White Paper: Introduction to Cloud Computing

White Paper: Introduction to Cloud Computing White Paper: Introduction to Cloud Computing The boom in cloud computing over the past few years has led to a situation that is common to many innovations and new technologies: many have heard of it, but

More information

How to Turn the Promise of the Cloud into an Operational Reality

How to Turn the Promise of the Cloud into an Operational Reality TecTakes Value Insight How to Turn the Promise of the Cloud into an Operational Reality By David Talbott The Lure of the Cloud In recent years, there has been a great deal of discussion about cloud computing

More information

BENEFITS OF A CLOUD ERP SYSTEM April 12, 2016

BENEFITS OF A CLOUD ERP SYSTEM April 12, 2016 BENEFITS OF A CLOUD ERP SYSTEM April 12, 2016 Ricardo de Rojas Senior Managing Consultant rderojas@bkd.com Colleen Gutirrez Senior Consultant II cgutirrez@bkd.com 1 TO RECEIVE CPE CREDIT Participate in

More information

E nable the service delivery of our customers

E nable the service delivery of our customers Information Technology Department Vijay Sammeta, Acting Chief Information Officer M I S S I 0 N E nable the service delivery of our customers through the integration of city-wide technology r~soiirc~s

More information