Cloud Security Alliance Releases Perspective on Cloud Risk Management Report That Identifies Cloud Computing Rapid Adoption Gaps and Risks
The document provides an impartial look at risk by identifying, examining gaps introduced over the last decade by rapid adoption of cloud computing
The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications and best practices to help ensure a secure cloud computing environment, today released Perspective on Cloud Risk Management, a new paper that looks to examine the effectiveness of governance and maturity with cloud computing risk management frameworks. The paper addresses how the underlying concepts of effective risk management can be integral to managing the broad risk introduced to enterprises by cloud computing.
“The rapid growth in both scope and market share, combined with the inherent complexity of cloud computing, is straining the capabilities of existing governance and risk management frameworks. As the users – and uses – of cloud computing evolve, so must the supporting governance models, including the maturity of governance and risk management programs,” said Daniele Catteddu, Chief Technology Officer, Cloud Security Alliance, one of the paper’s lead authors. “We hope to spur debate with this document within the cloud and risk management communities on the suitability of existing methodologies and practices.”
The document lays out five questions to stimulate discussion and facilitate possible solutions:
- Are the risk management methodologies currently available adequate to manage risks in the cloud?
- Are organizations aware of the shared responsibility model introduced by cloud computing, and are the responsibilities appropriately reflected in the risk management processes and programs?
- Are organizations aware of the concepts and implications of indirect/loss of control imposed by cloud computing and the challenges they pose to the design of risk mitigation procedures and their validation?
- Are organizations sufficiently aware of the impact that cloud computing has on the propagation of their supply chains and the difficulty in evaluating and monitoring the consolidated residual risk of third/fourth parties?
- Are the current governance practices adequate to effectively identify, evaluate, and report the relevant cloud risks to relevant stakeholders?
Risk management when applied to cloud operations plays a vital role in all of an organization’s processes and is essential to its overall business improvement strategy. As such, it must be a top-level, enterprise-wide process rather than a siloed or departmental exercise. While the risk management approach is the same whether, in the cloud or on-prem, there are significant differences in tactics and implementation that must be addressed. An effective risk management program will address issues related to economic value, process improvement, compliance, information security, and privacy, including:
- New operational security risks created by moving to the cloud
- Costs related to the failure to address cloud compliance
- Risks related to the cloud market growth
- Mitigation measures
CSA’s Perspective on Cloud Risk Management is a free document. Download it now.