Auditability and Compliance in the Cloud - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

IoT
IoT
Cloud
Commentary
5/6/2010
02:04 PM
John Soat
John Soat
Commentary
50%
50%

Auditability and Compliance in the Cloud

One of the nagging negative aspects of cloud computing is its ability, or lack thereof, to allow for adequate auditability and to ensure regulatory compliance issues are being addressed. It might surprise some skeptics that a significant portion of the SaaS community is comfortable with what their service providers offer in that regard.

One of the nagging negative aspects of cloud computing is its ability, or lack thereof, to allow for adequate auditability and to ensure regulatory compliance issues are being addressed. It might surprise some skeptics that a significant portion of the SaaS community is comfortable with what their service providers offer in that regard.

Now that cloud computing has passed the implement-it-quick-before-anyone-notices phase, so that a lot more management types are involved in the cloud discussion, including those hard heads in security, audit and compliance issues are coming to the fore. And rightly so: It's not an easy thing to turn over financial or business processes to strangers, or a decision to make lightly.

Audit and compliance issues can vary depending on the type of cloud computing you're considering implementing. For example, infrastructure-as-a-service generally allows for more control on the part of the customer. On the other hand, software-as-a-service locks down processing on the vendor's site, application features are mostly standard, and customization is generally limited.

So it is interesting to note that in a recent InformationWeek Analytics survey, more than half of the SaaS users (54%) indicated that, in terms of their comfort level with the service's overall auditability and compliance features, they were "as comfortable as we are with our internal systems." Another 8% claimed they were "more comfortable."

Of course, a not insignificant percent, almost a third (31%), said they were "less comfortable" with the service's audit and compliance features when compared with their own systems. (Puzzlingly, 7% answered, "don't know," to which I would respond: Get out technology, quick!)

Cloud vendors are responding to customers' anxieties (at least the savvy ones are) by making their processes, including security procedures, more transparent. Auditability and compliance features should be understood and agreed upon before a cloud computing engagement is undertaken.One of the nagging negative aspects of cloud computing is its ability, or lack thereof, to allow for adequate auditability and to ensure regulatory compliance issues are being addressed. It might surprise some skeptics that a significant portion of the SaaS community is comfortable with what their service providers offer in that regard.

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
Comment  | 
Print  | 
More Insights
Slideshows
7 Technologies You Need to Know for Artificial Intelligence
Jessica Davis, Senior Editor, Enterprise Apps,  7/1/2019
Commentary
A Practical Guide to DevOps: It's Not that Scary
Cathleen Gagne, Managing Editor, InformationWeek,  7/5/2019
Commentary
Diversity in IT: The Business and Moral Reasons
James M. Connolly, Editorial Director, InformationWeek and Network Computing,  6/20/2019
White Papers
Register for InformationWeek Newsletters
State of the Cloud
State of the Cloud
Cloud has drastically changed how IT organizations consume and deploy services in the digital age. This research report will delve into public, private and hybrid cloud adoption trends, with a special focus on infrastructure as a service and its role in the enterprise. Find out the challenges organizations are experiencing, and the technologies and strategies they are using to manage and mitigate those challenges today.
Video
Current Issue
A New World of IT Management in 2019
This IT Trend Report highlights how several years of developments in technology and business strategies have led to a subsequent wave of changes in the role of an IT organization, how CIOs and other IT leaders approach management, in addition to the jobs of many IT professionals up and down the org chart.
Slideshows
Flash Poll