Publication Cover
EDPACS
The EDP Audit, Control, and Security Newsletter
Volume 66, 2022 - Issue 1
361
Views
1
CrossRef citations to date
0
Altmetric
Research Article

BUILDING A COMPREHENSIVE CLOUD SECURITY AUDIT PROGRAM

 

Abstract

Building a security audit program for cloud services could be a complex process; there are various aspects that a security professional must consider when choosing what areas to incorporate in an in-house framework or what industry standard to use to assess particular cloud infrastructures. A cloud provider must take into account various aspects related to the core of the service, such as API security, code reviews, infrastructure, and others; on the other hand. A cloud customer must consider other areas specific to the use of the service, such as vendor lock-in, contractual agreements, and others. This article contemplates a holistic view of the various frameworks and tools available to companies and security professionals building a comprehensive audit program; it covers the cloud provider and the cloud customer perspectives and expands on what tools could be applied depending on the security audit’s angle.

DISCLOSURE STATEMENT

No potential conflict of interest was reported by the author(s).

Additional information

Notes on contributors

Gary Carrera

Gary Carrera is a Privacy Program Manager at Meta (former Facebook). He has 14 years of experience supporting large tech companies in Information Security and Privacy programs, most recently at Facebook and Apple. He holds an MS in Business Administration and Project Management and CDPSE, CISM, CISA, CCSP, HITRUST CCSFP, ISO27001 among other certifications. The postings on this site are the author’s own and don’t necessarily reflect his employer’s positions or opinions on the subject.

Reprints and Corporate Permissions

Please note: Selecting permissions does not provide access to the full text of the article, please see our help page How do I view content?

To request a reprint or corporate permissions for this article, please click on the relevant link below:

Academic Permissions

Please note: Selecting permissions does not provide access to the full text of the article, please see our help page How do I view content?

Obtain permissions instantly via Rightslink by clicking on the button below:

If you are unable to obtain permissions via Rightslink, please complete and submit this Permissions form. For more information, please visit our Permissions help page.