400 likes | 563 Views
Cloud Computing Risk Assessments. Donald Gallien March 31, 2011. Overview. Cloud Computing Refresher Assessing Cloud Computing Universe Completeness Using a Cloud Computing Risk Ranking Model Risk Ranking Case Study. Quiz. What do the following have in common? Paisley GRC
E N D
Cloud Computing Risk Assessments Donald Gallien March 31, 2011
Overview • Cloud Computing Refresher • Assessing Cloud Computing Universe Completeness • Using a Cloud Computing Risk Ranking Model • Risk Ranking Case Study
Quiz • What do the following have in common? • Paisley GRC • Salesforce.com • Amazon EC2 • Google Apps • Microsoft Business Productivity Online Suite (BPOS) • Rackspace • WebEx
Cloud Computing Basics • Internet-based computing, whereby shared resources, software and information are provided to computers and other devices on-demand, like the electricity grid (Source: Wikipedia) • Based on virtualization and abstraction of the underlying infrastructure • IT Audit Risk is largely driven by: • Deployment Model • Service Model • Nature of Applications & Data in Cloud
Deployment Models Source: NIST
Service Models Source: NIST
Another Way to Look as Service Models Example WebEx Provider Control BPOS Amazon EC2
Deployment Model Risk Profile Public Community Private Likelihood of Data Security, Privacy, and Control Breach
Service Model Risk Profile IaaS PaaS SaaS Impact of Loss of Control & Security Breach
Cloud Refresher Summary • Public clouds are inexpensive, but provide less security and service • Private clouds are expensive, but align better with technology and security standards • IaaS models are very broad in scope, but organizations maintain more control • SaaS models are narrow in scope, but organizations relinquish almost all control What is the impact of cloud computing on the IT audit function?
But one thing never changes • All IT Audit and Governance groups must: • Identify an Universe • Risk Rank the Universe • Provide Appropriate Coverage based on Risk
Technology Governance • Oversight • Technology Approvals • Partner Approvals How does your organization promote controlled cloud computing?
Firewalls and Encryption Certificates • Firewall & VPN Rule Changes • Firewall Logs • Encryption Certificate Requests Cloud computing environments are unlikely to stand-alone.
Invoices / T&E Reporting • Vendor Master • Invoice Lists • T&E Reporting How much does it cost to deploy cloud based e-mail service at Google?
Process Walkthroughs • Business Process • Data Flow • Technology Overview Has anyone discovered cloud based computing in a walkthrough meeting?
Summary – Universe Completeness • Cloud computing can be difficult to identify • Traditional technology governance, security, and procurement controls can be used to identify cloud computing • Users and business analysts could be your best source of cloud computing information What else can you do to identify cloud computing?
A few thoughts before we start • Risk models include elements of judgment and must fit the organization • Some model assumptions may be completely wrong for your organization • We should have a lot of debate on this topic • Risk ranking scores must drive governance requirements and audit activities
Deployment Model Considerations Public Private
Service Model Considerations IaaS SaaS
Data Security Considerations Secret Unclassified
Physical Hosting Site Considerations Undefined Domestic Location
Dependent Applications > 10 < 3
Recovery Time Objectives (RTO) Considerations 4 Hours 31 Days
Regions Supported Considerations Europe / Global All Other
Summary – Cloud Risk Ranking Models • Cloud risk ranking attributes and scoring must vary based on environment and need • Risk attributes and scoring require alignment with organizational standards What other risk attributes might you use, and how would your rank them on a high, medium, low basis?
Conclusions • Business and technology leaders are embracing cloud computing - it is here to stay and growing • Cloud computing standards and risk ranked cloud universes are foundational requirements for governance • We must adjust our approach to remain relevant
Questions Contact Information: donald.w.gallien@aexp.com