A Comparison of IT Governance & Control Frameworks in Cloud Computing. Jack D. Becker ITDS Department, UNT & Elana Bailey



Similar documents
A Comparison of IT Governance and Control Frameworks in Cloud Computing

IT Controls and Governance in Cloud Computing

Security, Compliance & Risk Management for Cloud Relationships. Adnan Dakhwe, MS, CISA, CRISC, CRMA Safeway Inc. In-Depth Seminars D32

Cloud Computing An Auditor s Perspective

Cloud Services Overview

Cloud Security Alliance: Industry Efforts to Secure Cloud Computing

PCI Compliance and the Cloud: What You Can and What You Can t Outsource Presented By:

Orchestrating the New Paradigm Cloud Assurance

Cloud Security considerations for business adoption. Ricci IEONG CSA-HK&M Chapter

Securing The Cloud. Foundational Best Practices For Securing Cloud Computing. Scott Clark. Insert presenter logo here on slide master

Assessing Risks in the Cloud

Compliance and the Cloud: What You Can and What You Can t Outsource

Key Considerations of Regulatory Compliance in the Public Cloud

Security Issues in Cloud Computing

Cloud Security and Managing Use Risks

Validation of a Cloud-Based ERP system, in practice. Regulatory Affairs Conference Raleigh. 8Th September 2014

Cloud Security Certification

Managing Cloud Computing Risk

Strategic Compliance & Securing the Cloud. Annalea Sharack-Ilg, CISSP, AMBCI Technical Director of Information Security

Service Measurement Index Framework Version 2.1

Hans Bos Microsoft Nederland.

Adopting Cloud Computing with a RISK Mitigation Strategy

Cloud Risk Management: How to Consolidate your CSP and Corporate Risk Profile

Trends in Information Technology (IT) Auditing

Cloud Security Introduction and Overview

Dispelling the Myths about Cloud Computing Security

Cloud Security. DLT Solutions LLC June #DLTCloud

Pharma CloudAdoption. and Qualification Trends

Cloud Computing in a Regulated Environment

Cloud, where are we? Mark Potts, HP Fellow, CTO Cloud November 2014

STORAGE SECURITY TUTORIAL With a focus on Cloud Storage. Gordon Arnold, IBM

Public Cloud Workshop Offerings

Selecting a Cloud Service Provider (CSP)

Purpose. Service Model SaaS (Applications) PaaS (APIs) IaaS (Virtualization) Use Case 1: Public Use Case 2: Use Case 3: Public.

Key Speculations & Problems faced by Cloud service user s in Today s time. Wipro Recommendation: GRC Framework for Cloud Computing

Protec'ng Data and Privacy in a World of Clouds and Third Par'es Vincent Campitelli

Virginia Government Finance Officers Association Spring Conference May 28, Cloud Security 101

Enhancing IT Governance, Risk and Compliance Management (IT GRC)

Cloud Security. Peter Jopling IBM UK Ltd Software Group Hursley Labs. peterjopling IBM Corporation

Cisco Cloud Assessments. Justin Tang

GRC Stack Research Sponsorship

Security & IT Governance: Strategies to Building a Sustainable Model for Your Organization

Auditing Cloud Computing and Outsourced Operations

A Flexible and Comprehensive Approach to a Cloud Compliance Program

IT Security Risk Management Model for Cloud Computing: A Need for a New Escalation Approach.

How to ensure control and security when moving to SaaS/cloud applications

Gobierno de TI Enfrentando al Reto. IT Governance Facing the Challenge. Everett C. Johnson, CPA International President ISACA and ITGI

Cloud Courses Description

The agile Cloud Brokerage approach. An innovative, business aligned and mature IT services delivery model!

A HYPE-FREE STROLL THROUGH CLOUD STORAGE SECURITY

Cloud Courses Description

HIPAA CRITICAL AREAS TECHNICAL SECURITY FOCUS FOR CLOUD DEPLOYMENT

What We ll Cover. Defensible Disposal of Records and Information Litigation Holds Information Governance the future of records management programs

Certified Information Security Manager (CISM)

Securing The Cloud With Confidence. Opinion Piece

CLOUD STORAGE SECURITY INTRODUCTION. Gordon Arnold, IBM

How RSA has helped EMC to secure its Virtual Infrastructure

VENDOR RISK MANAGEMENT UPDATE- ARE YOU AT RISK? Larry L. Llirán, CISA, CISM December 10, 2015 ISACA Puerto Rico Symposium

Refresher on cloud computing

Aalborg Universitet. Cloud Governance Berthing, Hans Henrik Aabenhus. Publication date: Document Version Preprint (usually an early version)

Cloud Infrastructure Security

SECURITY MODELS FOR CLOUD Kurtis E. Minder, CISSP

How To Compare Itil To Togaf

BADM 590 IT Governance, Information Trust, and Risk Management

AN OVERVIEW OF INFORMATION SECURITY STANDARDS

On Premise Vs Cloud: Selection Approach & Implementation Strategies

Top 10 Cloud Risks That Will Keep You Awake at Night

Cloud Computing and Security Risk Analysis Qing Liu Technology Architect STREAM Technology Lab

Cloud Computing What Auditors need to know

Cloud Computing Risk Assessment

Security and Privacy in Cloud Computing

How to procure a secure cloud service

Effectively Assessing IT General Controls

Ensuring Cloud Security Using Cloud Control Matrix

Whitepaper. Canopy Security. Simplicity, Agility, Transparency. An Atos company. Powered by EMC 2 and VMware

Incident Handling in the Cloud and Audit s Role

Security in the Cloud

Legal Issues in the Cloud: A Case Study. Jason Epstein

Domain 5 Information Security Governance and Risk Management

What Is The Cloud And How Can Your Agency Use It. Tom Konop Mark Piontek Cathleen Christensen

White Paper on CLOUD COMPUTING

Are You Prepared for the Cloud? Nick Kael Principal Security Strategist Symantec

Cloud Computing demystified! ISACA-IIA Joint Meeting Dec 9, 2014 By: Juman Doleh-Alomary Office of Internal Audit

Hybrid Clouds. Krishnan Subramanian Analyst & Researcher Krishworld.com. A whitepaper sponsored by Trend Micro Inc.

Transcription:

A Comparison of IT Governance & Control Frameworks in Cloud Computing Jack D. Becker ITDS Department, UNT & Elana Bailey ITDS Department, UNT MS in IS AMCIS 2014 August, 2014 Savannah, GA

Presentation Overview Key Issues of IT Governance in the Cloud Current Control Frameworks and Models Cloud Control in IT Governance Cloud IT Governance - Control Dial

Governance

Key Issues Transparency of controls Which Control Framework? Compliance (legal, regulatory, and audit) Transborder information flow Privacy and security International regulation and policy Corporate cultural impacts

Current Popular Control Frameworks and Models Source: http://trongbang86.blogspot.com/2010/11/comparison-of-business-and-technical.html

Comparison of Popular IT Standards & Control Frameworks ISACA CobiT for Cloud Computing (2011) Cloud Cube Model (Jerico Forum; 2012) COSA ERM Framework (2012) ENISA (Europe/COSO Model; 2009) ITIL ITSM Framework for Cloud (2010) ISO 27000/9000 (2011)

ISACA IT Control Objectives Information Systems Audit and Control Association Business Processes/Application Domains A Control Objectives for Information and Related Technology Service Delivery Models Software as a Service (SaaS) Platform as a Service (PaaS) Infrastructure as a Service (IaaS) Business Process Management as a Service (BPMaaS) Private Managed/Community Hybrid Public Source: Cloud Security Alliance, https://cloudsecurity alliance.org

Cloud Cube Model Source: www.jerichoforum.org

COSO ERM Framework Committee of Sponsoring Organizations of the Treadway Commission How risks and controls are viewed Align organization objectives Identify opportunities or risks Determine impact of risks Mitigate risks Assign control responsibility (organization or CSP) Establish timely and accurate communication flows Monitor effectiveness

ENISA Governance Framework European Network and Information Security Agency Based on COSO's Internal Control Integrated Framework Source: http://www.enisa.europa.eu/activities/risk-management/current-risk/business-process-integration/governance/ics

ITIL Information Technology Infrastructure Library Source: http://sysonline.net/content.php?id=53

ISO 27001-27002 International Organization for Standardization Source: http://www.simosindia.in/services/plan/?id=iso

CSA Cloud Security Guidance Cloud Security Alliance Operational Domains Tradional Security, Business Continuity and Disaster Recovery Data Center Operations Incident Response, Norifications and Remediation Application Security Encryption and Key Management Identity and Access Management Virtualization Governance Domains Governance and Enterprise Risk Management Legal and Electronic Discovery Compliance and Audit Information Lifecycle Management Portability and Interoperability

PDCA Cycle aka Deming or Shewhart Cycle PLAN create the requisite objectives and processes DO implement the processes CHECK evaluate and monitor the defined processes ACT modify the processes for improvement

Summary of Frameworks and Models

Cloud Governance Figure 7: Practical Governance, (2010). Retrieved from Gartner database.

5 IT Governance Domains Integrating Cloud IT Governance Models and Frameworks:

Extending IT Governance to the Cloud Issues to Consider Internal Threats Horizontal Audit Compliance Performance Metrics (SLAs) Security (SecaaS) Accountability & Responsibility RACI Matrix

Accountability & Responsibility ACCOUNTABILITY Preventive Controls Detective Controls Procedural Measures Technical Measures RESPONSIBILITY Customer vs. Provider Compliance Data Management Forensics & Recovery RACI Matrix: Responsible; Accountable; Counsel; Informed

Deconstructing the Cloud: Assess Each Item to be Moved! 1. What is Moving to the Cloud? Application Domain or Business Process 2. How will it be delivered? SaaS, IaaS, PaaS, BPMaaS 3. How will it be deployed? Public, Private, Community/Managed, or hybrid Note: There are 16 possible Delivery and Deployment possibilities

Deconstructing the Cloud: Next Step (Jericho Cube Model): 4. Where will the Data be Located? Internal or External? 5. Who Owns the technology, services and interfaces? Proprietary or Open? 6. Are there expectations of collaboration and data sharing? Perimeterized or De-Permiterized? 7. Who is managing the delivery? Insourced or Outsourced?

IT Risk Management -- Westerman s Hierarchy Agility Strategic Risk Accuracy Data Integrity Risk Access Risk Management Availability Business Continuity

Cloud Governance Dial

IT Cloud Governance Dial 1. What is Moving to the Cloud? 2. IT Governance Domain Objectives & Deliverables 3. Delivery Method? 4. Deployment Approach? 5. Cloud Formation Approach? 6. Enterprise Risk Management Controls? 7. IT Cloud Governance 8. Evaluation, Improvements, and Adaptation

Visualizing an Example of Using the Governance Dial

Conclusion Achieve IT-business alignment Add value