0% found this document useful (0 votes)
17 views14 pages

Domain6 Keynotes

The document outlines the importance of policies in corporate governance, detailing how they are established in response to regulations or contractual requirements, and the necessity of senior management support for their effectiveness. It discusses the complexities of international legislation conflicts in cloud computing, emphasizing the need for compliance with various legal frameworks and guidelines, such as GDPR and ISO standards. Additionally, it covers e-discovery and cloud forensics, highlighting the challenges and best practices for handling digital evidence in cloud environments.

Uploaded by

ssuresh19747745
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
17 views14 pages

Domain6 Keynotes

The document outlines the importance of policies in corporate governance, detailing how they are established in response to regulations or contractual requirements, and the necessity of senior management support for their effectiveness. It discusses the complexities of international legislation conflicts in cloud computing, emphasizing the need for compliance with various legal frameworks and guidelines, such as GDPR and ISO standards. Additionally, it covers e-discovery and cloud forensics, highlighting the challenges and best practices for handling digital evidence in cloud environments.

Uploaded by

ssuresh19747745
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

DOMAIN 6 KEY NOTES

Policies are the foundation of corporate governance. They require penalties as well as senior management sponsorship to be
effective. Policies are created in response to a requirement such as a standard or requirement benchmark. This standard is the
result of either a regulation, which is a legislative requirement, or a contractual requirement such as a contract agreement or
industry requirement such as a Payment Card Industry Data Security Standard.
A regulation or contractual requirement may be audited by either internal or external
auditing or assessment bodies. For example, a regulation may specify an eight-character
password that directly generates the organization’s password policy regarding that
information. The external regulatory audit checks that an eight-character password is in
use. However, an internal requirement might be more strenuous, requiring a 10-character
password.
Procedures are methods and instructions on how to maintain or accomplish the directives
of the policy.
A baseline is the benchmark to evaluate if the goals of the policy have been achieved.
A guideline is an arbitrary method of accomplishing a task. It is not a requirement but more of a suggestion
International Legislation Conflicts
With the global nature of cloud computing services, it is almost certain that international boundaries and jurisdictions will be
crossed from both policy and technological perspectives.
At all times, when dealing with legal, compliance, and regulatory issues, the first step should always be to consult with relevant
professionals or teams specializing in those areas.
A primary challenge is created by the existence of conflicting legal requirements coupled with the inability to apply local laws to a
global technology offering.
Challenges for the multitude of jurisdictions and requirements include the location of the users and the type of data they enter
into the systems, the laws governing the organization that owns the applications and any regulatory requirements they may have,
as well as the appropriate laws and regulations for the jurisdiction housing the IT resources and where the data is actually stored,
which might be in multiple jurisdictions as well.
Legislative Concepts
• International law: International law is the term given to the rules that govern relations between states or
countries.
• State law: State law typically refers to the law of each U.S. state,
• Copyright and piracy law: Copyright infringement can be performed for financial or nonfinancial gain
• Enforceable governmental request: An enforceable governmental request is a request or order that is capable of
being performed on the basis of the government’s order.
• Intellectual property right: Intellectual property rights give the individual who created an idea an exclusive right
to that idea for a defined period of time.
• Privacy law: The right of an individual to determine when, how, and to what extent she will release personal
information.
• The doctrine of the proper law: When conflict of laws occurs, this determines in which jurisdiction the dispute
will be heard, based on contractual language professing an express selection or a clear intention through a choice-
of-law clause.
• Criminal law: Criminal law is a body of rules and statutes that defines conduct prohibited by the government and
protects the safety and well-being of the public. criminal law also sets out the punishment to be enforced in cases
where the law is breached. Crimes are categorized based on their seriousness
DOMAIN 6 KEY NOTES
• Tort law: A body of rights, obligations, and remedies that sets out reliefs for persons suffering harm because of the
wrongful acts of others.
Frameworks & Guidelines relevant to Cloud Computing
• ISO/IEC 27017:2015 provides guidance on the information security aspects of cloud computing, recommending and
assisting with the implementation of cloud-specific information security controls supplementing the guidance in ISO/IEC
27002:2013 and other ISO27k standards.
• OECD-Privacy and Security Guidelines: Set of revised guidelines governing the protection of privacy and trans-border
flows of personal data. They represent a consensus on basic principles that can be built into existing national legislation
or serve as a basis for legislation in those countries that do not yet have it. Guidelines are as follows.
• Collection Limitation Principle • Security Safeguards Principle
• Data Quality Principle • Openness Principle
• Purpose Specification Principle • Individual Participation Principle
• Use Limitation Principle • Accountability Principle
• APEC Privacy Framework: It provides a regional standard to address privacy as it relates to the following

▪ Privacy as an international issue


▪ Electronic trading environments and the effects of cross-border data flows
• Goal is to free flow of information within the region
• Currently, six APEC member economies—Canada, Japan, Republic of Korea, Mexico, Singapore, and the United States—have aligned their privacy laws with the APEC Privacy Framework.

• EU Data Protection Directive (95/46/EC): provides for the regulation of the protection and free

movement of personal data within the European Union. It is designed to protect the privacy and protection
of all personal data collected for or about citizens of the European. The guidelines relate to the following
• The quality of data • The confidentiality and security of
• The Legitimacy or processing processing
• Special categories of processing • The notification of processing to a
• Data Subjects right of access to data supervisory authority
• Exceptions and restrictions • Scope of processing

• Right to object to the processing of data.


• General Data Protection Regulation (GDPR): The EU Data protection directive is replaced by GDPR. GDPR is designed to
• Harmonize data privacy laws across Europe
• Protect and empower all EU citizens’ data privacy
• Reshape the way organizations across the region approach data privacy
DOMAIN 6 KEY NOTES
• Countries with national laws that adhere to the GDPR include:
• All EU countries. • Switzerland (Swizz DPA) • Australia (Australian Privacy Act
• Andorra • Japan (Act on Protection of 1988 & Australian Privacy
• Singapore Personal Information (APPI), Principles (APPs))
• Israel (Israeli Privacy Law) • Argentina (PDP Act 2000)
• Uruguay
• Canada (PIPEDA)
• Countries without national laws that adhere to the GDPR include:
• The United States (no single federal law governing data protection)
• Everywhere else
• African personal Data Protection: Nearly two-thirds of the 54 nations of the African continent has data privacy protection
as a regulation, is in process of making it, or has it as part of their constitutions.
• Australia and New Zealand Privacy Principles: Regulations in Australia and New Zealand make it extremely difficult for
enterprises to move sensitive information to cloud service providers that store data outside of Australian/New Zealand
borders The Australian National Privacy Act of 1988 provides guidance and regulates how organizations collect, store,
secure, process, and disclose personal information.
• Australian Privacy Principles (APPs)
• Swiss Data Protection Law: The basic principles of which are in line with EU law, three issues are of importance:
• Data processing by third parties
• Transferring personal data abroad
• Data Security
• Switzerland is not part of the EU but part of EFTA. On privacy issues, they do not follow EFTA practices but their
own. EFT countries normally follow EU regulations.
• EU-US Privacy Shield: Privacy Shield framework became operational on August 1, 2016 which protects the fundamental
rights of anyone in the EU whose personal data is transferred to the United States for commercial purposes. It allows the
free transfer of data to companies that are certified in the United States under the Privacy Shield. EU_US Privacy Shield
is a replacement for Safe Harbour Privacy Principles.
• Canada PIPEDA: The Personal Information Protection and Electronic Documents Act conforms to the EU Data Directive
and Privacy Regulation. The EU acknowledges PIPEDA as satisfactorily addressing the principles of the Data Directive and
the Privacy Regulation
• US
• COPPA (Children’s Online Privacy Protection Rule) imposes certain requirements on operators of websites or
online services directed to children under 13 years of age
• FERPA
• Prevent academic institutions from sharing student data with anyone other than parents of students (up to age
18) or the students (after age 18).
• HIPAA: Health Insurance Portability and Accountability Act (1996) sets out the requirements of the U.S. Department of
Health and Human Services (HHS) to adopt national standards for electronic health care transactions and national
identifiers for providers, health plans, and employers. Protected health information can be stored via cloud computing
under HIPAA.
• Sarbanes–Oxley Act (SOX): The Sarbanes–Oxley Act of 2002 is legislation enacted in the United States to protect
shareholders and the general public from accounting errors and fraudulent practices in the enterprise.
DOMAIN 6 KEY NOTES
• GLBA: The Gramm–Leach–Bliley Act (also known as the Financial Modernization Act of 1999) is a federal law enacted in
the United States to control the ways that financial institutions deal with the private information of individuals. GLBA also
requires financial institutions to give customers written privacy notices that explain their information-sharing practices.
The act consists of three sections
• The financial privacy rule
• The safeguards rule
• The pretexting provisions
Charter of Fundamental Rights of the European Union
In Article 8 under the heading Protection of personal data, the Charter of Fundamental Rights of the European Union states:
• Everyone has the right to the protection of personal data concerning him or her.
• Such data must be processed fairly for specified purposes and on the basis of the consent of the person concerned or
some other legitimate basis laid down by law. Everyone has the right of access to data which has been collected
concerning him or her, and the right to have it rectified.
• Compliance with these rules shall be subject to control by an independent authority
Standard Privacy Requirements
ISO/IEC 27018:2019 First international code of practice that focuses on protection of personal data in the cloud. It is based on the
ISO/IEC 27002 and provides controls applicable to public cloud PII which is not addressed by the existing ISO/IEC 27002 control
set. 5 key principles of CSPs adopting ISO/IEC 27018:2019
1. Consent
2. Control
3. Transparency
4. Communication
5. Independent, yearly audit
Generally Accepted Privacy principles (GAPP): Developed by American Institute of Certified Public Accountants (AICPA) and the
Canadian Institute of Chartered Accountants (CICA). GAPP is designed to assist organizations in strengthening their privacy
policies, procedures, and practices. The GAPP report proves privacy is a business subject, as the impact of privacy violations
reaches beyond technical or legal boundaries. 10 Privacy principles groups for GAPP.
Privacy Maturity Model: Maturity models are a recognized means by which organizations can measure their progress against
established benchmarks. The AICPA/CICA Privacy Maturity Model is based on GAPP and the Capability Maturity Model (CMM).
Privacy-Level Agreements (PLAs) The Cloud Security Alliance (CSA) has a document that provides a baseline for complying with
various frameworks and legislative mandates concerning data privacy. The PLA provides a basis for communication between
service provider and consumer where documentation exists related to how the provider protects the data. With clear and concise
communication, the proper level of protection is understood and known, compliance with legislative requirements is maintained,
and legal pitfalls related to lack of compliance can be avoided.

Data Subject: individual who the PII refers to


Data Controller, Cloud Customer, Data Owner: any entity collecting or creating PII
Data Processor, Cloud Provider, Data Custodian: any entity acting on behalf or at the behest of the Data Controller
Data Controller is ultimately responsible for any unauthorized disclosure of PII
eDiscovery
• e-discovery refers to any process in which electronic data is sought, located, secured, and searched with the intent of
using it as evidence in a civil or criminal legal case.
DOMAIN 6 KEY NOTES
• Discovery can be carried out online and offline (for static systems or within particular network segments). In the case of
cloud computing, almost all e-discovery cases are done in online environments with resources remaining online
• ISO/IEC 27050
• CSA Document on eDiscovery
• When these electronic documents have been stored with a cloud service provider, additional complexity arises because
the data owner no longer has full control over its documents. It must find a way to make the cloud service provider
cooperate on e-discovery cloud issues.
• Preservation of Evidence: The law imposes on the parties to a dispute a duty to preserve information that may become
evidence in a lawsuit. Failure to implement a “litigation hold” carries significant legal consequences. A litigation hold is
the process by which information is identified, preserved and maintained. It is intended to ensure evidence, when
needed, will be available. Thus, anything that may result in hampering the discovery process or the production of
evidence will expose your company to significant risks of adverse action by a judge.
• [Link]
• Conducting e-Discovery investigations
There are various ways to conduct e-discovery investigations in cloud environments.
• Software as a service (SaaS)-based e-discovery: These SaaS packages typically cover one of several e-discovery
tasks, such as collection, preservation, and review
• Hosted e-discovery (provider): Typically, the customer stores data in the cloud with the understanding and
mechanisms to support the cloud vendor doing the e-discovery
• Third-party e-discovery: When no prior notifications or arrangements with the CSP for an e-discovery review
exist, typically an organization needs a third party or specialized resources operating on its behalf
• Note that careful consideration and appreciation of the service-level agreement (SLA) and
contract agreements must be undertaken to establish whether investigations of cloud based assets are permitted or if
prior notification and acceptance are required.
Cloud forensics and ISO/IEC 27050-1
Cloud computing forensic science is the application of scientific principles, technological practices, and derived and proven
methods to reconstruct past cloud computing events through identification, collection, preservation, examination,
interpretation, and reporting of digital evidence
Conducting a forensic network analysis on the cloud is not as easy as conducting the same investigation across your own network
and local computers. This is because you may not have access to the information that you require and, therefore, need to ask the
service provider to provide the information. Communication in this scenario becomes important, and all involved entities must
work together to gather the important information related to the incident
The key thing for the CCSP to be aware of is that while doing cloud forensics, all relevant national and international standards
must be adhered to.
Forensics Requirements
Keep the following challenges in mind when gathering evidence:
• The seizure of servers containing files from many users creates privacy issues.
• The trustworthiness of evidence is based in part on the cloud provider.
• Investigators are in part dependent on cloud providers to acquire evidence.
• The technician collecting data may not be qualified for forensic acquisition.
• Unknown location of the physical data can hinder investigations.
DOMAIN 6 KEY NOTES
When gathering evidence, several steps should be taken:
• Throughout the process, keep a detailed log of every step that was taken to collect the data, including
information about each tool used in the process.
• Use photographic evidence to provide visual reminders of the computer setup and peripheral devices.
• Before actually touching a system, make a note of or photograph any pictures, documents, running programs,
and other relevant information displayed on the monitor. If a screensaver is active, that should be documented
as well because it may be password protected.
• If possible, designate one person on the scene as the evidence custodian. This person should have the sole
responsibility to photograph, document, and label every item that is collected and record every action that was
taken along with the name of who performed the action, where it was performed, and at what time.
• ISO/IEC 27037 offers guidance on identifying potential data sources and acquiring the data from the sources. ISO has
provided a suite of standards specifically related to digital forensics The fundamental purpose of the digital forensics
standard ISO/IEC 27037, 27041, 27042 , 27043 and 27050 is to promote good practice methods and processes for forensic
capture and investigation of digital evidence.
Maintaining evidence from collection to trial is a critical part of digital forensics.

Five Rules of Evidence


• Be authentic: Evidence needs to be tied back to the scene to be used.
• Be accurate: Through the use of collection processes, your evidence must maintain authenticity and veracity.
• Be complete: All evidence should be collected, including evidence that supports and that can diminish the reliability of
other incriminating evidence.
• Be convincing: The evidence should be clear and easy to understand, and believable to a jury.
• Be admissible: The evidence must be able to be used in a court of law. Probative value means that the evidence is
sufficiently useful to prove something important in a trial
DOMAIN 6 KEY NOTES

Regulated PII and Contractual PII


• Contractual PII: Where an organization or entity processes, transmits, or stores PII as part of its business or services, this
information is required to be adequately protected in line with relevant local state, national, regional, federal, or other
laws. Contractual elements related to PII should list requirements and appropriate levels of confidentiality, along with
security provision/requirements necessary. Contractual PII has specific requirements for the handling of sensitive and
personal information, as defined at the contractual level. Failure to meet or satisfy contractual requirements may lead to
penalties
• Regulated PII: A key differentiator from a regulated perspective is the “must haves” to satisfy regulatory requirements
of which failure to do so can result in sizable and significant financial penalties. Regulations are put in place to reduce
exposure and to ultimately protect entities and individuals from a number of risks. Regulated PII will typically have
requirements for reporting any compromise of data, either to an official government entity or possibly to the impacted
users directly.
• The intent of a contract is to provide for a legally binding instrument that governs the acts, expectations, and behaviours
between two or more parties. A regulation is typically confined to a specific industry or process that involves a provider
and consumer
PCI DSS
PCI DSS: applies if you store, process or transmit Cardholder information
PCI DSS is a contractual requirement
QSA: Qualified Security Assessor
RoC: Report of compliance
SAQ: Self-Assessment Questionnaire
PCI DSS –> Report of Compliance (RoC) if merchant is doing more than 6 million of transactions a year
PCI DSS –> Self-Assessment Question (SAQ) if merchant is doing less than 6 million of transactions a year
SAD: Sensitive Authentication Data
If merchant suffer a data breach –> Report of Compliance
DOMAIN 6 KEY NOTES
12 requirements & 280 sub-requirements
1. Install and maintain a firewall configuration to protect cardholder data
2. Do not use vendor-supplied defaults for system passwords and other security parameters
3. Protect stored cardholder data (retain minimum card
holders’ data. Encrypt properly, never store CVV or PIN
4. Encrypt transmission of cardholder data across open,
public networks
5. Use and regularly update anti-virus software or programs
6. Develop and maintain secure systems and applications
7. Restrict access to cardholder data by business need to
know
8. Assign a unique ID to each person with computer access
9. Restrict physical access to cardholder data
10. Track and monitor all access to network resources and
cardholder data
11. Regularly test security systems and processes
12. Maintain a policy that addresses information security for all personnel
• Assessment every year
• ASV: Approved Scanning Vendor (they are approved by PCI SCC)
A quarterly ASV Scan is a PCI DSS requirement
• PFI: PCI Forensic Investigator
Auditing in the Cloud
The CCM provides an invaluable resource when identifying and listing each action and what impacts these may have
• internal and external audits
o An organization’s internal audit acts as a third line of defence after the business or Information technology (IT)
functions and risk management functions through the following means:
▪ Independent verification of the cloud program’s effectiveness
▪ Providing assurance to the board and risk management functions of the organization with regard to the
cloud risk exposure
o The internal audit function can also play a trusted advisor and proactively be involved by working with IT and
the business in identifying and addressing the risk associated with the various cloud services and deployment
models
o The internal audit function can engage with stakeholders, review the current risk framework with a cloud lens,
assist with the risk-mitigation strategies, and perform a number of cloud audits
o Another potential source of independent verification on internal controls will be audits performed by external
auditors.
o Internal audits should be used first
o
o An external auditor’s scope varies greatly from an internal audit, whereas the external audit usually focuses on
the internal controls over financial reporting.

Types of Audit Reports


DOMAIN 6 KEY NOTES
Service Organization Control (SOC): 1/2/3 for Cyber Security
The Service Organization Control audits framework is designed for consumers to have confidence in the provider they’ve selected
and for the provider to give assurance of the design and effectiveness of controls. This audit produces reports that are
accomplished under an attestation standard known as Statement on Standards for Attestation Engagements (SSAE) 18. Now
service organizations will need to implement a formal third-party vendor management program and a formal annual risk
assessment process
• SOC 1: Focus solely on controls at CSP that are likely to be relevant to an audit of a subscriber’s financial statements.
Based on Statement on Standards for Attestation Engagements number 16 (SSAE 16). Reporting focuses on outsourced
services performed by service organizations which are relevant to a company’s (user entity) financial reporting., Use of
these reports is restricted to the management of the
service organization, user entities, and user auditors.
Two types.
• SOC 2: Focus addresses operational risks of
outsourcing to 3rd parties outside financial reporting.
These reports are based on the Trust Services Criteria
which include up to five categories: security,
availability, processing integrity, confidentiality,
and/or privacy.
• SOC 3: covers similar reporting areas as the SOC 2, but isn’t as comprehensive. It excludes certain details of the description
and all of the detailed controls/results of testing. Whereas a SOC 2 report restricts users, the benefit of a SOC 3 is that it
is a general-use report making it a great tool for marketing purposes. It contains no actual data about the security controls
of the audit target and is just an assertion that the audit was conduct and that the target company passed
SOC for Cybersecurity
The American Institute of Certified Public Accountants (AICPA) has responded to the increase in cybersecurity attacks by publishing
the Cybersecurity Risk Management Reporting Framework, also known as the System and Organization Controls (SOC) for
Cybersecurity. In a SOC for Cybersecurity report, a CPA reports on an organization’s enterprise-wide cybersecurity risk
management program.
DOMAIN 6 KEY NOTES

CSA STAR
The CSA STAR was created to establish a “first step” in displaying transparency and assurance for cloud-based environments. The
CSA made the STAR a publicly available and accessible registry that provides a mechanism for users to assess the security of the
cloud security provider.
STAR provides granular levels of detail, with controls specifically defined to address the differing categories for cloud-based
services. CSA STAR is broken into three distinct layers, all of which focus on the AIC components
• Level 1, Self-Assessment: Requires the release and publication of due diligence self-assessment, against the CSA
consensus assessment initiative (CAI) questionnaire or CCM
• Level 2, Attestation: Requires the release and publication of available results of an assessment carried out by an
independent third party based on CSA CCM and ISO27001:2013 or AICPA SOC2
• Level 3, Ongoing Monitoring Certification: Requires the release and publication of results related to security-properties
monitoring based on the cloud trust protocol (CTP)

Different Risk Management Frameworks


• ISO 31000:2018
• NIST Framework for Improving Critical Infrastructure Cybersecurity, Version
• NIST SP 800-37r2, Risk Management Framework for Information Systems and Organizations
• The FedRAMP Program
Cloud Audit Goals
• Ability to understand, measure, and communicate the effectiveness of Cloud Service Provider controls and security to
organisational stakeholders/executives
• Proactively identify any control weaknesses or deficiencies, while communicating these both internally and to the CSP
• Obtain levels of assurance and verification as to the CSP’s ability to meet the SLA and contractual requirements, while
not relying on reporting or CSP reports
Audit Planning

Gap Analysis
• Identify relevant “gaps” against specified frameworks or standards
• Resource or personnel who are nor engaged or functioning within the are of scope perform Gap Analysis
• An auditor or subject matter expert performs the gap analysis against a number of listed requirements, which can range
from a complete assessment to a random sample of controls (subset).
• The report will most likely be signed off on by a senior member of the organization, which will prompt risk treatment and
a process of work to remediate or reduce the identified and reported risks.
Cloud-auditing Goals
• Cloud auditing should result in the following key outcomes
DOMAIN 6 KEY NOTES
▪ Be able to understand, measure, and communicate the effectiveness of CSP controls and security to
organizational stakeholders and executives
▪ Proactively identify any control weaknesses or deficiencies, while communicating these both internally and to
the CSP
▪ Obtain levels of assurance and verification as to the CSP’s ability to meet the SLA and contractual requirements,
while not relying on reporting or CSP reports
• Audit Planning
▪ Defining audit objectives
▪ Defining audit scope
▪ conducting the audit
• When conducting an audit, keep the following issues in mind:
▪ Adequate staff
▪ Adequate tools
• Refining the audit Process/Lessons Learned
• Ensure that previous reviews are adequately analysed and taken into account, with the view to streamline and obtain
maximum value for future audits
• These phases may coincide with other audit-related activities and be dependent on organizational structure.
Value of ISMS 27001
• The use of an ISMS is even more critical within a cloud environment to ensure that changes being made to cloud
infrastructure are being documented for reporting and auditability purposes.
• top-down sponsorship and endorsement of information security across the business, highlighting its overall value and
necessity
Implementing policies
• Policies are crucial to implementing an effective data security strategy.
• From a cloud computing angle, the use of policies can go a long way toward determining the security posture
of cloud services, as can standardizing practices to guide implementation.
Identifying and involving the relevant stakeholders
• Identifying and involving the relevant stakeholders from the commencement of any cloud computing discussions are of
utmost importance
• To objectively assess within what areas of the business it may be appropriate to utilize cloud-based services, it is a key
requirement to have visibility on what services are currently provided, how these are delivered, and on what platforms,
systems, architectures, and interdependencies they are operating.
• The determination of the key stakeholders should form the blueprint to identify potential impacts on current services,
operations, and delivery models.
• Business impact analysis (BIA) or related continuity and recovery plans exist, these should typically list or capture the
technical components, related interdependencies, and order of restoration
Governance challenges
• Define audit requirements and extension of additional audit activities.
• Verify that all regulatory and legal obligations will be satisfied as part of the nondisclosure agreement (NDA) or contract.
• Establish reporting and communication lines both internal to the organization and for CSPs.
• Ensure that where operational procedures and processes are changed due to use of cloud services, all documentation
and evidence are updated accordingly.
DOMAIN 6 KEY NOTES
• Ensure that all business continuity, incident management and response, and disaster recovery plans (DRPs) are updated
to reflect changes and interdependencies.
Understanding the implications of the Cloud to enterprise risk management
• It is important for both the CSP and the cloud customer to be focused on risk
• After all, the way services are delivered changes delivery mechanisms, locations, and providers—all of which result in
governance and risk-management changes.
• Addressing these risks requires that the CSP and cloud customer’s policies and procedures be aligned as closely as possible
because risk management must be a shared activity to be implemented successfully.
• Risk Profile
o The risk profile is determined by an organization’s willingness to take risks as well as the threats to which it is
exposed.
o The risk profile should identify the level of risk to be accepted, the way risks are taken, and the way risk-based
decision making is performed
• Risk appetite
o Business to balance the risks and offset any excessive risk components, all while satisfying listed requirements
and objectives for security and growth
• Difference between the Data owner and controller and the Data custodian and Processor o The data subject is an
individual who is the focus of personal data
o The data controller is a person who either alone or jointly with other persons determines the purposes for which
and the manner in which any personal data is processed.
o The data processor in relation to personal data is any person other than an employee of the data controller who
processes the data on behalf of the data controller.
o Data stewards are commonly responsible for data content, context, and associated business rules.
o Data custodians are responsible for the safe custody, transport, data storage, and implementation of business
rules
o Data owners hold the legal rights and complete control over a single piece or set of data elements.
o Data owners also possess the ability to define distribution and associated policies
• SLA
o SLA forms the most crucial and fundamental component of how security and operations will be undertaken
o SLA should also capture requirements related to compliance, best practice, and general operational activities to
satisfy each of these.
o SLA components
▪ Uptime Guarantees
• Service levels regarding performance and uptime are usually featured in outsourcing contracts
▪ SLA Penalties
• For SLAs to be used to steer the behaviour of a cloud services provider, they need to be
accompanied by financial penalties
• Contract penalties provide an economic incentive for providers to meet stated SLAs.
• This is an important risk-mitigation mechanism
▪ Suspension of Service
• Some cloud contracts state that if payment is more than 30 days overdue (including any
disputed payments), the provider can suspend the service
DOMAIN 6 KEY NOTES
▪ Provider Liability
▪ Data-Protection Requirements
• Most cloud contracts make the customer ultimately responsible for security, data protection,
and compliance with local laws
▪ DR
• Cloud contracts rarely contain provisions about DR or provide financially backed RTOs. Some
IaaS providers do not even take responsibility for backing up customer data.
▪ Security Recommendations
▪ CSP is ultimately responsible for the organization’s data and alerting its customers, partners, or
employees of any breach, it is particularly critical for companies to determine what mechanisms are in
place to alert customers if any security breaches do occur and to establish SLAs determining the time
frame the CSP has to alert you of any breach
o Within an SLA, the following contents and topics should be covered as a minimum:
• Availability
• Performance
• Security and privacy of data
• Logging and reporting
• Disaster recovery expectation
• Location of the data
• Data format and structure
• Portability of the data
• Identification and problem resolution
• Change-management process
• Dispute-mediation process
• Exit strategy with expectations on the provider to ensure smooth transition
ISO/IEC for supporting CCSP about SLA
ISO/IEC DIS 19086-1: Information technology — Cloud computing SLA Framework — Part 1: Overview and concepts
ISO/IEC NP 19086-2: Information technology Cloud computing SLA Framework and technology — Part 2: Metrics
ISO/IEC CD 19086-3: Information technology — Cloud computing SLA Framework and technology — Part 3: Core requirements
Risk Mitigation
• Different Risk Framework
o ISO 31000:2009
• The foundation components of ISO 31000:2009 focus on designing, implementing, and reviewing risk
management.
• European Network and Information Security Agency (ENISA)
• National Institute of Standards and Technology (NIST) - Cloud Computing Synopsis and Recommendations
Understanding outsourcing and contract Design
• Understanding and appreciating outsourcing has long been the duty and focus of procurement and legal function
• Whether it is related to the single outsourcing of personnel, roles, functions, or entire business functions, these have
been availed and utilized globally to maximize cost benefits, plug skills gaps, and ultimately ensure that entities run as
smoothly and efficiently as possible.
DOMAIN 6 KEY NOTES
Business requirements
• Prior to entering into a contract with a cloud supplier, your enterprise should evaluate its specific needs and requirements
that form the basis and foundation of the organizational cloud strategy
• To develop a cloud strategy, the key organizational assets need to be agreed upon and assessed for adequacy or suitability
for cloud environments
• Any exceptions, restrictions, or potential risks should be highlighted and clearly documented
• This process should also list regulatory and compliance components that need to be addressed and satisfied
Metrics for Risk Management
Quantitative assessments typically employ a set of methods, principles, or rules for assessing risk based on the use of numbers.
This type of assessment most effectively supports cost–benefit analyses of alternative risk responses or courses of action.
Qualitative assessments typically employ a set of methods, principles, or rules for assessing risk based on nonnumeric categories
or levels (e.g., very low, low, moderate, high, very high)
Single Loss Expectancy (SLE): SLE must be calculated to provide an estimate of loss. SLE is defined as the difference between the
original value and the remaining value of an asset after a single exploit. SLE = Asset Value (in $) x Exposure Factor (as a % of loss)
Exposure Factor (EF): The exposure factor is a variable percentage of the monetary loss that may happen based upon a specific
threat vector. For instance, the complete physical destruction of a building vector may have a greater monetary loss than an
external threat attack vector. The total loss is expressed as a percentage.
Annualized rate of occurrence (ARO): Is an estimate of how often a threat will be successful in exploiting a vulnerability over the
period of a year
Annualized Loss Expectancy (ALE): ALE = ARO x SLE

Risk Treatment
ISO/IEC 27005:2018 rebrands the definitions in risk treatment to modification, retention, avoidance, and sharing.
• Modification: Course of action that implements controls that are technical, environmental, or cultural
• Retention: Retaining the risk without further action
• Avoidance: The activity or condition that precipitates the risk is avoided
• Sharing: The risk is shared with another party (e.g., could be contractual, sub-contractual, insurance of some type)
Common Criteria: The CC is an international set of guidelines and specifications (ISO/IEC 15408) developed for evaluating
information security products to ensure they meet an agreed-upon security standard for government entities and agencies.
Supply chain Risk
• You should obtain regular updates of a clear and concise listing of all dependencies and reliance on third parties, coupled
with the key suppliers.
• Where single points of failure exist, these should be challenged and acted upon to reduce outages and disruptions to
business processes.
• Engagement with key suppliers is crucial at this point, as is ensuring that contracts cover such risks or provide a right to
audit clause to ascertain and measure relevant risks.
• One resource that the CCSP should consider with regard to supply chain risk is NIST SP 800-161
Supply chain: ISO/IEC 27036–4:2016: Information technology — Security techniques — Information security for supplier
relationships —

Due Care and Due Diligence

You might also like