Domain 2 - Governance & Risk Management Flashcards
How does cloud computing impact governance & risk management?
In four areas:
a) Governance - because it introduces a third party.
b) Enterprise Risk Management
c) Information Risk Management
d) Information Security
What is Governance?
- Policies, processes, and internal controls that comprise how an organization is run.
- Mechanisms for management including structures and leadership.
What is Enterprise risk management?
- Managing overall risk to the organization.
- It is more than those concerned with technology
- Other risks - e.g. regulatory, supply chain, financial, etc.
What is Information Risk Management?
- Manages risk to information including information technology
What is information security?
- Tools and practices to manage risk to information.
- Information risk can be managed by other means besides information security - e.g. contracts, insurance, and physical security etc.
What is the relationship between governance, ERM, IRM and IS?
IS is a tool of IRM
IRM is a tool of ERM
ERM is a tool of Governance.
What are the tools of cloud governance?
1) Contracts - between a CSP and CSC.
2) Supplier assessment - may include financial viability, history, features, 3PAttestations, peer feedback
3) Compliance reporting - audit of controls by 3Ps.
How does service models affect governance?
- SaaS - most critical example of the need for a negotiated contract
- PaaS - likelihood of fully negotiated contract is lower
- IaaS - existing governance structures may be transferrable.
How does deployment models (public, private, hybrid) affect governance?
- Public clouds - contracts may be inflexible; CSP has incentive to keep everything current; governance has to accommodate this fact.
- Private cloud - more flexible contract; but CSP may offer just what’s in the contract; governance focus on internal SLAs and charge backs for accounting.
- Hybrid - governance issues multiple domains
- Community - governance must consider relationships with other members of the community in addition to provider.
What’s a process to manage cloud risk?
- Review CSP’s documentation
- Review CSP’s security program
- Review legal, regulatory, industry, contract
- Evaluate service based on context of information assets
- Evaluate provider (finances, reputation, insurers etc.)
- Periodically review audits and assessments