Cloud Adoption and Audit Planning

Sharing is caring!

&NewLine;<p>As organizations begin to transition services to the cloud&comma; there is a need for ongoing assurances from both cloud customers and cloud service providers that controls are put in place and are operating as intended&period; The internal audit function can also play a &OpenCurlyDoubleQuote;trusted” advisor role and proactively be involved by working with IT and the business in identifying and addressing the risk associated with the various cloud services and deployment models&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>An organization’s internal audit can provide visibility into&colon;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list"><li>The cloud program’s effectiveness<&sol;li><li>Assurance to the board and risk management team on the organization’s cloud risk exposure<&sol;li><li>If the business practices are helping the business manage the risk and meet its strategic objectives<&sol;li><&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<p>External audits are typically provided by an external company that has an association of registered auditors&period; External audits typically&colon;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list"><li>Provide assurance that legal&comma; regulatory&comma; or contractual requirements are being met<&sol;li><li>Occur annually unless otherwise specified<&sol;li><li>Provide assurance to parties consuming services that the provider has and is maintaining required controls<&sol;li><&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<p>In line with financial&comma; compliance&comma; regulatory&comma; and other risk-related audits&comma; the requirement for scoping and ensuring the appropriate focus and emphasis on components most relevant to cloud computing &lpar;and associated outsourcing&rpar; should include the following phases&colon;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image size-large is-resized"><img src&equals;"https&colon;&sol;&sol;www&period;thecloudxperts&period;co&period;uk&sol;wp-content&sol;uploads&sol;2022&sol;09&sol;image-1024x239&period;png" alt&equals;"" class&equals;"wp-image-823" width&equals;"880" height&equals;"205"&sol;><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>Ensure the audit has a clear <strong>objective <&sol;strong>and well-defined <strong>scope<&sol;strong>&period; <&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list"><li>Document list of current services&sol;resources utilized from cloud service provider&lpar;s&rpar;<&sol;li><li>Define key components of services &lpar;storage&comma; utilization&comma; processing&comma; etc&period;&rpar;<&sol;li><li>Define cloud services to be audited &lpar;IaaS&comma; PaaS&comma; SaaS&rpar;<&sol;li><li>Define geographic locations permitted&sol;required<&sol;li><li>Define locations for audits to be undertaken<&sol;li><li>Define key stages to audit &lpar;information gathering&comma; workshops&comma; gap analysis&comma; verification evidence&comma; etc&period;&rpar;<&sol;li><li>Document key points of contact within cloud service provider and internal to organization<&sol;li><li>Define escalation and communication points<&sol;li><li>Define criteria and metrics by which the cloud service provider will be assessed<&sol;li><li>Ensure criteria is consistent with the SLA and contract<&sol;li><li>Factor in &OpenCurlyDoubleQuote;busy periods” or organizational periods &lpar;financial year end&comma; launches&comma; new services&comma; etc&period;&rpar;<&sol;li><li>Ensure findings captured in previous reports or stated by the cloud service provider are actioned&sol;verified<&sol;li><li>Ensure previous nonconformities&sol;high-risk items are reassessed&sol;verified as part of the audit process<&sol;li><li>Ensure any internal operational or business changes have been captured as part of the audit plan &lpar;reporting changes&comma; governance&comma; etc&period;&rpar;<&sol;li><li>Agree on final reporting dates &lpar;conscious of business operations and operational availability&rpar;<&sol;li><li>Ensure findings are captured and communicated back to relevant business stakeholders&sol;executives<&sol;li><li>Confirm report circulation&sol;target audience<&sol;li><li>Document risk management&sol;risk treatment processes to be utilized as part of any remediation plans<&sol;li><li>Agree on an auditable process for remediation actions &lpar;ensuring traceability and accountability&rpar;<&sol;li><&sol;ul>&NewLine;