From the course: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

Unlock this course with a free trial

Join today to access over 23,200 courses taught by industry experts.

Cloud audits

Cloud audits

- [Instructor] When conducting audits or assessments of organizations that leverage the cloud, audit professionals run into some unique challenges. The use of virtualization and cloud computing raise unique assurance issues. The very fact that an organization is using service providers for the storage processing and or transmission of some of their data expands the scope of the audit. If the organization is depending upon the security controls of their provider in some way, which is always the case in cloud computing, then that provider's controls are within the scope of the audit. This might lead you to think that the auditors would then need to travel to the cloud provider site, and verify the controls there just as they would at the organization's own data centers. After all, they do need some assurance that the controls are functioning properly, but just imagine what that would mean. How would you visit the data centers of Microsoft, Amazon or Google? They're distributed all over…

Contents