auditing cloud services

38
June 24, 2022 Auditing Cloud Services Brian Daniels, CISA, GCFA David Crotts, CISA

Upload: enye

Post on 05-Feb-2016

45 views

Category:

Documents


3 download

DESCRIPTION

Auditing Cloud Services. Brian Daniels, CISA, GCFA David Crotts, CISA. Overview. Introduction to cloud services in a decentralized environment Audit perspective of cloud service risks Conducting the audit Outcomes Questions or comments. Why Utilize Cloud Services? - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Auditing Cloud Services

April 22, 2023

Auditing Cloud ServicesBrian Daniels, CISA, GCFADavid Crotts, CISA

Page 2: Auditing Cloud Services

2

Overview• Introduction to cloud services in a

decentralized environment• Audit perspective of cloud service risks• Conducting the audit• Outcomes• Questions or comments

Page 3: Auditing Cloud Services

INTRODUCTION

Why Utilize Cloud Services?Who Uses Cloud Services?How Can You Identify Cloud Service Implementations?What is Virginia Tech’s Cloud Service Environment Like?

3

Page 4: Auditing Cloud Services

Why Use Cloud Services• Collaboration• Need for excess storage• Lack of resources to manage internally• Cost effective

4

Page 5: Auditing Cloud Services

Who Uses Cloud Services• Researchers• IT Professionals• Administrators• Students• Alumni• EVERYONE!

5

Page 6: Auditing Cloud Services

How to Identify Cloud Services• Request info from Central IT• Request info from Departments• Query technology related expenditures• Account Codes• MCC

• Unlikely to identify all

6

Page 7: Auditing Cloud Services

Control Environment at VT• Departmental purchasing authority.• Difficult to identify all purchases.• Purchase records only show vendor, not

product detail.• What about free services?• Mobile device apps?

7

Page 8: Auditing Cloud Services

Control Environment at VT• Guidelines suggest reviews by:• Central IT (Security, Network)• Data Stewards• Legal Counsel

• Is it realistic?

8

Page 9: Auditing Cloud Services

CLOUD SERVICES RISKS

Risk EnvironmentRisk AssessmentContract Risks

9

Page 10: Auditing Cloud Services

Risk Environment• Risks of outsourcing are similar to risks

of operating internally .• Additional risks exist when the system

is outside of your control.• Low cost/free services vs. high cost?• How do you monitor these risks?

10

Page 11: Auditing Cloud Services

Risk Assessment• A need has been identified.• What could go wrong utilizing a cloud

service provider?• What is the worst possible outcome?• What is a more likely outcome?• What am I exposing myself to?

11

Page 12: Auditing Cloud Services

Risk Assessment• What data elements will be utilized?• Are there any regulatory requirements?• FERPA• HIPAA• ITAR• PCI• PII

12

Page 13: Auditing Cloud Services

Risk Assessment• What risks are significant enough to

warrant special consideration in contract negotiations?

13

Page 14: Auditing Cloud Services

Contract Risks• Who has signature authority?• Click through agreements?

• Does the defined service adequately represent the identified need?

• How complete is the audit clause?• Client access to audit vendor performance.• Client access to review third party audits.

14

Page 15: Auditing Cloud Services

Contract Risks• Does the agreement require

acknowledgement of regulatory compliance?

• Who owns the data once it’s in the cloud?

15

Page 16: Auditing Cloud Services

Contract Risks• What invokes the termination clause

and what does it address?• Access to data upon termination.• Secure removal of data.• Termination fees or waiver of fees.• Responsibilities of each party upon

termination.

16

Page 17: Auditing Cloud Services

Contract Risks• Service Level Agreements• Are they complete?• Are they reasonable?• What is the measurement period?• What is the penalty for non-compliance?

17

Page 18: Auditing Cloud Services

Contract Risks• Are the specific obligations explicitly

stated in the contract?• If not, where are they located?• Policies, procedures, or privacy statements

are typically subject to change without notice.• Click through agreements may also change

without notice.

18

Page 19: Auditing Cloud Services

Contract Risks• Do the elements of the contract apply to

any subcontracted vendors?• Negotiation of appropriate contract terms

is an effective means to reducing risk exposure.

• It is often not possible to get all desired terms and conditions in the contract.

19

Page 20: Auditing Cloud Services

CONDUCTING THE AUDIT

SamplingDocument RequestsAudit Testing

20

Page 21: Auditing Cloud Services

Sampling• What factors exist in the population?• Users• Type of service• Functional Use• Cost

21

Page 22: Auditing Cloud Services

Sampling• Select a cross section• Single user to organization wide• Application or storage• Administrative, teaching, research• High cost, low cost

22

Page 23: Auditing Cloud Services

Documentation Request• Planning Documentation• Risk assessments• Steering committee minutes• Product reviews• Security reviews

23

Page 24: Auditing Cloud Services

Documentation Request• Original and most recently executed

contract.• Most recent SLA performance review• Most recent third party audit report• Preferred report is the SOC 2 Type 2

24

Page 25: Auditing Cloud Services

Testing• Risk assessment• Centrally created questionnaire• Only required for purchases greater than

$2,000• Yes/No responses• Developed in 2011

25

Page 26: Auditing Cloud Services

Testing• Steering Committee Minutes• No steering committee for most

department specific purchases• Expected for central systems purchases

(i.e. email, business intelligence software)

26

Page 27: Auditing Cloud Services

Testing• Security Reviews• Performed on 4 of 5 services with a cost

greater than $2,000• Not performed on smaller dollar purchases• IT Security Office provides an opinion on the

security architecture of the service• Has resulted in corrective action by the vendor.

27

Page 28: Auditing Cloud Services

Testing• Signature Authority• Department and Central authorization OK• Data steward review was often absent

• Based on the data utilized by the service• Legal Counsel review was often absent

28

Page 29: Auditing Cloud Services

Testing• Terms and Conditions• Audit Clauses

• One audit clause gave the vendor the right to audit Virginia Tech!

• Termination agreements• Beware of data retrieval and removal provisions

• Definition of adequate and robust SLAs

29

Page 30: Auditing Cloud Services

Testing• Terms and Conditions• Subcontractors

• Use of subcontractors permitted?• Enforcement of parent contract to

subcontractors?• Regulatory compliance requirements?• Personnel vetting?

30

Page 31: Auditing Cloud Services

Testing• Contract Monitoring• Periodic review of Terms and Conditions

• Still reflect current operating environment?• What changes have occurred?

• SLA Performance• Third party audit reviews

• Identified one subcontractor who had significant data breaches occur in 2009.

31

Page 32: Auditing Cloud Services

OUTCOMES

32

Page 33: Auditing Cloud Services

Outcomes• Risk assessment questionnaire• Revised questions to target specific risks

and help assess data elements used and need for ongoing monitoring.

• Expanded scope to include items under $2,000.

33

Page 34: Auditing Cloud Services

Outcomes• Communication and Training• Ensure adequate knowledge of the risks of

outsourcing for department staff.• Focus on training business staff and IT

professionals.

34

Page 35: Auditing Cloud Services

Outcomes• Assess the impact of restricting use of

certain MCC codes on selected Pcard holders.• Manage the risk at the point of

procurement by limiting the number of people able to purchase such services.

35

Page 36: Auditing Cloud Services

Outcomes• Establishment of preferred standard

contract language.• Joint effort led by IT Acquisitions in

collaboration with Procurement, Legal Counsel, and Central IT.

36

Page 37: Auditing Cloud Services

Outcomes• Processes and procedures designed to

help manage and monitor contracts.• Led by IT Acquisitions with input from

Central IT or other administrative functions.

37

Page 38: Auditing Cloud Services

QUESTIONS OR COMMENTS?

38