Effective techniques for aligning IT controls to cloud environments
As an IT auditor performing risk and controls assessments within an enterprise cloud environment, establishing audit goals is essential to helping you develop a clear alignment between controls to be tested and the process to effectively test those controls within the cloud. As mentioned in the Preparing to perform a cloud audit section earlier in this chapter, the paradigm of classifying business versus IT functions has changed with the migration to the cloud, requiring a shift in how we think about and assess technical controls within an enterprise cloud. From a broad sense, in the cloud environment, we should focus on determining whether the risks and controls we are assessing for effectiveness are financially focused, operationally focused, or cybersecurity-focused to come up with a logical grouping or mapping of what should be in scope for testing. Let’s look at them in detail:
- Financially focused...