Cloud Computing
Cloud Computing
–
–
Risk and
Risk and
Rewards
Rewards
John Lazarine John Lazarine Vice President and Chief Audit Executive Vice President and Chief Audit Executive Mark Salamasick Mark Salamasick Director of Center for Internal Auditing Director of Center for Internal AuditingJohn Lazarine
John Lazarine
•
25 years of Internal Audit experience
•
Industry experience: Retail, Financial Services, Oil &
Gas, Telecommunications, Aerospace & Defense,
Construction and Technology Services
•
Companies: JCPenney, Mobil Oil, Alcatel, Raytheon,
Centex and Rackspace
*Rackspace
Rackspace
•
Founded in 1998, based in San Antonio
•
Service leader in Cloud Computing
•
180,000+ customers, 4,300 employees
•
8 Data Centers based in the US, UK and HK
•
Key Products: Cloud Hosting, Managed Hosting
and Email & Apps all backed by Fanatical
Support.
Mark Salamasick
Mark Salamasick
•
Over 25 years internal audit and consulting experience
•
Industry experience: Financial Services, Utility, Oil &
Gas, Technology, and Education
•
Companies: Central Michigan University, Accenture,
Bank of America, and University of Texas at Dallas
•
Published: Most recent book “Auditing Outsourced
Functions”
University of Texas at Dallas
University of Texas at Dallas
•
Founded in 1969, based in Richardson
•
Over 19,000 students and over 6,300 in the
business school
•
One of the fastest growing Universities in the US
•
One of the largest graduate Accounting programs
with over 850 students
•
Largest Graduate Internal Audit program
worldwide
Session Overview
Session Overview
Cloud computing is changing the way we all look at outsourced technology. This session will help in gaining an understanding and evaluating the rewards that can be gained from the cloud. The reduction of technology costs and immediate availability of technology infrastructure provide alternatives that must be considered. At the same time all cloud based solutions are not the same and your organization must evaluate the risks. Cloud solutions are here to stay and transform the way we do business. Also, come hear the latest guidance provided by COSO in addressing the opportunities, rewards and risk mitigation of doing business in the cloud. Learning Objectives: 1. Understand the opportunities provided by cloud computing. 2. Understand the new risks from cloud computing along with risk mitigation techniques. 3. Learn the right questions to ask when doing business in the Cloud.What is Cloud?
What is Cloud?
The National Institute of Standards and Technology (NIST) defines cloud computing as a model for enabling “…… convenient, on‐demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction”Service Models & Uses
Service Models & Uses
Software as a Service (SaaS) Platform as a Service (PaaS) Infrastructure as a Service (IaaS) Overview Applications over a network Developer platform with built‐in services Rent processing, storage, network capacity and other computing resources Level of Customer Control Does not manage or control the underlying Cloud infrastructure, servers, O/S, network, storage or individual application capabilities (with the exception of user configurable settings) Has control over the deployed applications and possibly the application hosting environment configurations Has control over the operating systems, storage and deployed application *Deployment Models & Uses
Deployment Models & Uses
Deployment Model Description
Private Cloud • Operated solely for an organization
• May be managed by the organization or a third party
• May exist on or off premise
Public Cloud • Made available to the general public
• Owned by an organization selling cloud services
Hybrid Cloud • A composition of two or more clouds (private, public and/or community) that remain unique entities, but are bound together by standardized or proprietary technology that enables data and application portability (e.g., cloud bursting for load balancing between clouds).
Community Cloud • Shared by several organizations
• Supports a specific community that has a shared mission or interest
• May be managed by the organization or a third party
ISACA Survey
ISACA Survey
Benefits of Cloud Computing
Benefits of Cloud Computing
Cost control Cost control –– Utility modelUtility model
SpeedSpeed ‐‐ Immediate provisioning (setting up resources)Immediate provisioning (setting up resources)
FocusFocus ‐‐ Allows company to focus on core competenciesAllows company to focus on core competencies
ScalabilityScalability –– Ability to dynamically adjust resources according to Ability to dynamically adjust resources according to demand with little to no notice
demand with little to no notice
PerformancePerformance –– Utilizing severer load balancingUtilizing severer load balancing
Operational Expertise Operational Expertise –– Patch management, version updates, Patch management, version updates, data security
Economic Economic Architectura l Strategic
Elements of
Elements of
Cloud Computing
Cloud Computing
Value
Value
*Cloud Security
Cloud Security
—
—
Today
Today
Provider transparency
Provider transparency
–
–
Trust , reliability and viability
Trust , reliability and viability
–
–
SLAs
SLAs
Data protection
Data protection
Malicious insiders
Malicious insiders
—
—
social engineering
social engineering
Cloud
Cloud
‐
‐
specific attacks
specific attacks
Cloud Security
Cloud Security
—
—
Tomorrow
Tomorrow
Globally compatible legislation
Globally compatible legislation
Cloud compatibility standards
Cloud compatibility standards
Real
Real
‐
‐
time management
time management
Identity management
Identity management
Responding to security incidents
Responding to security incidents
Bandwidth
Bandwidth
Pricing
Pricing
Controls
Controls
Virtual firewalls
Virtual firewalls
Encryption
Encryption
—
—
as close to the source as possible
as close to the source as possible
Network access
Network access
Secure SAN protocols
Secure SAN protocols
Regular deletion of unused assets
Regular deletion of unused assets
Logs and audit trails
Logs and audit trails
Compliance requirements
Compliance requirements
Public Clouds
Public Clouds
—
—
Entertainment
Entertainment
Tech and media companies are racing to create
Tech and media companies are racing to create
Internet
Internet
‐
‐
video hit programs on the scale of
video hit programs on the scale of
traditional TV
traditional TV
–
–
Netflix and Kevin Spacey
Netflix and Kevin Spacey
–
–
Hulu and Kiefer Sutherland
Hulu and Kiefer Sutherland
–
–
Yahoo, Sony, AOL, YouTube
Yahoo, Sony, AOL, YouTube
–
–
Consumers are watching more
Consumers are watching more
video on Internet TVs and tablet computers
video on Internet TVs and tablet computers
Right Questions to Ask
Right Questions to Ask
Risks
Risks
Disruptive Force
Disruptive Force
Residing in the same risk ecosystem as the CSP
Residing in the same risk ecosystem as the CSP
Lack of Transparency
Lack of Transparency
Security, Compliance and Data Jurisdiction
Security, Compliance and Data Jurisdiction
Reliability, performance, and high
Reliability, performance, and high
-
-
value cyber
value cyber
-
-attack target
attack target
Risk of data leakage
Risk of data leakage
IT organizational changes
IT organizational changes
Potential vendor lock
Potential vendor lock
-
-
in
in
Cloud Computing Board Oversight
Cloud Computing Board Oversight
Questions?
Questions?
Who in management is responsible for understanding and Who in management is responsible for understanding and management the business risks associated with cloud
management the business risks associated with cloud
computing?
computing?
What are competitors doing with cloud solutions?What are competitors doing with cloud solutions?
Are cloud computing initiatives aligned with the Are cloud computing initiatives aligned with the organization
organization’’s risk appetite?s risk appetite?
Does management have the skills required to understand Does management have the skills required to understand the complexities associated with cloud computing?
the complexities associated with cloud computing?
Cloud Computing Management
Cloud Computing Management
Questions?
Questions?
What is managementWhat is management’’s stand on outsourcing functions?s stand on outsourcing functions?
Does the organization anticipate rapid growth that might Does the organization anticipate rapid growth that might require using cloud solutions?
require using cloud solutions?
Is the organization in a mature market that might require Is the organization in a mature market that might require using cloud computing to save costs to remain
using cloud computing to save costs to remain
competitive?
competitive?
How should the organization prepare for cloud computing?How should the organization prepare for cloud computing?
Who should be involved in the evaluation process, and Who should be involved in the evaluation process, and who makes the decision?
who makes the decision?
How can the organization manage its risks adequately How can the organization manage its risks adequately while operating in a business environment with cloud
while operating in a business environment with cloud
computing?
computing?
Other Considerations
Other Considerations
Cloud solution pricing predictabilityCloud solution pricing predictability
Captive renterCaptive renter
Involvement of representatives across the organizationInvolvement of representatives across the organization
Clear definitions of responsibilities and required Clear definitions of responsibilities and required interactions between the organization and the CSP
interactions between the organization and the CSP
Evaluation of business continuity requirementsEvaluation of business continuity requirements
Key Tasks in the Road to the Cloud
•
Assessing the Cloud Strategy
•
Evaluating Cloud Providers
•
Moving to the Cloud
•
Monitoring the Provider
*Conclusions
Conclusions
Many benefits to utilizing Cloud technologies
Many benefits to utilizing Cloud technologies
Management should have a strategy for adopting
Management should have a strategy for adopting
Cloud technologies
Cloud technologies
Establish processes for periodically evaluating and
Establish processes for periodically evaluating and
monitoring risks
monitoring risks
Management should ensure costs and benefits are
Management should ensure costs and benefits are
reviewed for long term
reviewed for long term
Internal Audit and Finance should partner with
Internal Audit and Finance should partner with
management to help ensure the objectives of utilizing
management to help ensure the objectives of utilizing
the Cloud is met
the Cloud is met
Contact Information:
Contact Information:
John
John LazarineLazarine Rackspace
Rackspace HostingHosting (210) 312 (210) 312--34733473 [email protected] [email protected] Contact Information: Mark Salamasick
Jindal School of Management The University of Texas at Dallas
Informational Sources
Informational Sources
COSO Enterprise Risk Management for Cloud ComputingCOSO Enterprise Risk Management for Cloud Computing Global Technology Guide 18 Cloud Computing from IIA Global Technology Guide 18 Cloud Computing from IIA International International Cloud Security Alliance (CSA)Cloud Security Alliance (CSA) – – Cloud Controls MatrixCloud Controls Matrix – – Consensus Assessments Initiative Questionnaire Consensus Assessments Initiative Questionnaire CloudAudit.orgCloudAudit.org Isaca.orgIsaca.org cloud computingcloud computing European Network and Information Security Agency (ENISA)European Network and Information Security Agency (ENISA) – – Cloud Computing: Information Assurance Framework Cloud Computing: Information Assurance Framework NIST 800NIST 800‐‐144144