• Tuisblad
  • Sake
  • The challenges of auditing the cloud technology
Lamek Tangeni, Acting Chief Audit Executive at GIPF. Photo Contributed
Lamek Tangeni, Acting Chief Audit Executive at GIPF. Photo Contributed

The challenges of auditing the cloud technology

Opinion
To audit and oversee the cloud, the audit team must possess the appropriate skills and expertise.
Lamek Tangeni
Recent advances in data storage, communication, and information processing technologies have enabled many companies to utilise business processes that are being supported by IT-enabled applications. Many companies now see a tremendous increase in their capital budgets for IT, which always raises questions on the return of these investments and to what extent emerging and innovative solutions can free up much-needed capital resources. With modern technologies becoming more widespread but at the same time more complex, it is thus important for auditors to understand not only the nature and potential benefits of new technologies, but also the risks they present and the impact they may have on the performance of the audit.

Cloud computing is a convenient, on-demand network access to a shared pool of resources that can be rapidly provisioned and released with minimal management effort or service provider interaction. It allows access to your business data or systems from anywhere 24/7/365 as long as you have internet access, enabling a remote workforce.

Life before the cloud environment was characterized by limited access to certain devices and networks, incorporated defensive layers to protect internal applications and data, and relied on a known and manageable security perimeter to prevent unauthorized access. Life in the cloud can be less secure, due to new risks to be managed.

Top six challenges

With an understanding of how the cloud differs from traditional IT, and an appreciation of the threat landscape, the following are the top questions that an auditor should be concerned with?

1. The shared responsibility of the stakeholders:

Are the responsibilities of each stakeholder in the supply chain clear, documented and communicated? One of the biggest risks in the cloud environment is lack of transparency. It is therefore important that each stakeholder knows their responsibility. This should be documented and included in the contract.

2. Laws and regulations:

What is the location of the cloud? Which local laws and regulations are applicable? Are there controls in place to identify the applicable jurisdictions and regulations? How is compliance to this identified and managed? Ideally, the cloud location, applicable jurisdiction and regulations should be included in the contract.

3. Cloud usage:

Is there a list of cloud solutions currently in use? Can you identify shadow IT cloud usage? Are controls in place to identify shadow IT cloud solutions? To what extent are the cloud computing activities across the origination coordinated? Identifying the use of cloud computing is important in understanding the cloud computing risks that are relevant to your environment to ensure appropriate controls are in place and operating effectively.

4. Risk management:

Are cloud solutions and the associated risks identified and evaluated as part of the Enterprise Risk Management (ERM) process? Is there a defined risk appetite and risk tolerance for cloud solutions, or were these risks accepted? Was this risk accepted by the appropriate authority within the organization?

5. Do you have the right to audit?

Do the contracts you have with cloud providers include a right to audit clause? The larger the cloud computing provider, the less likely they will allow the inclusion of such a clause, so it’s important to understand your rights and to request access to the cloud provider’s System and Organization Controls (SOC) reports to confirm appropriate controls are in place and operating effectively to ensure your data is secured.

6. Is your audit team equipped to audit the cloud?

To audit and oversee the cloud, your audit team must possess the appropriate skills and expertise. The Cloud Security Alliance and ISACA jointly developed a Certificate of Cloud Auditing Knowledge (CCAK) credential, which includes a risk-based approach to cloud migration and auditing strategies.

To ensure your organisation selects secure cloud platforms, your institutions internal audit department should be involved in the procurement, design and adoption of a cloud solution.

Kommentaar

Republikein 2024-10-05

Geen kommentaar is op hierdie artikel gelaat nie

Meld asseblief aan om kommentaar te lewer

LaLiga: Leganés 0 vs 0 Valencia SerieA: Hellas Verona 2 vs 1 Venezia | Napoli 3 vs 1 Como European Championships Qualifying: Sunderland 2 vs 2 Leeds United | Bristol City 0 vs 0 Sheffield Wednesday | Stoke City 6 vs 1 Portsmouth | Sheffield United 1 vs 0 Swansea City | Preston North End 3 vs 0 Watford English Championship: Sunderland 2 vs 2 Leeds United | Bristol City 0 vs 0 Sheffield Wednesday | Stoke City 6 vs 1 Portsmouth | Sheffield United 1 vs 0 Swansea City | Preston North End 3 vs 0 Watford #N/A Currency: GBP to NAD 22.88 | EUR to NAD 19.17 | CNY to NAD 2.49 | USD to NAD 17.48 | DZD to NAD 0.13 | AOA to NAD 0.02 | BWP to NAD 1.28 | EGP to NAD 0.35 | KES to NAD 0.13 | NGN to NAD 0.01 | ZMW to NAD 0.65 | ZWL to NAD 0.04 | BRL to NAD 3.19 | RUB to NAD 0.18 | INR to NAD 0.21 | USD to DZD 132.61 | USD to AOA 910 | USD to BWP 13.21 | USD to EGP 48.29 | USD to KES 128.5 | USD to NGN 1656.86 | USD to ZAR 17.48 | USD to ZMW 26.4 | USD to ZWL 321 | Stock Exchange: JSE All Share Index Same 0 | Namibian Stock Exchange (NSX) Overall Index 1868.17 Down -0.05% | Casablanca Stock Exchange (CSE) MASI 14167.03 Up +0.09% | Egyptian Exchange (EGX) 30 Index 31720.5 Up +1.24% | Botswana Stock Exchange (BSE) DCI 9661.12 Same 0 | NSX: MTC 7.75 SAME | Anirep 8.99 SAME | Capricorn Investment group 17.34 SAME | FirstRand Namibia Ltd 49 DOWN 0.50% | Letshego Holdings (Namibia) Ltd 4.1 UP 2.50% | Namibia Asset Management Ltd 0.7 SAME | Namibia Breweries Ltd 31.49 UP 0.03% | Nictus Holdings - Nam 2.22 SAME | Oryx Properties Ltd 12.1 UP 1.70% | Paratus Namibia Holdings 11.99 SAME | SBN Holdings 8.45 SAME | Trustco Group Holdings Ltd 0.48 SAME | B2Gold Corporation 47.34 DOWN 1.50% | Local Index closed 677.62 UP 0.12% | Overall Index closed 1534.6 DOWN 0.05% | Osino Resources Corp 19.47 DOWN 2.41% | Commodities: Gold US$ 2 653.84/OZ DOWN -0.0008 | Copper US$ 4.54/lb UP +0.38% | Zinc US$ 3 189.00/T DOWN -0.06% | Brent Crude Oil US$ 78.66/BBP UP +0.23% | Platinum US$ 988.89/OZ DOWN -0.0035 #N/A