CSA Official Press Release
Cloud Security Alliance Releases Perspective on Cloud Risk Management Report That Identifies Cloud Computing Rapid Adoption Gaps and Risks
Document provides impartial look at risk by identifying, examining gaps introduced over the last decade by rapid adoption of cloud computing
SEATTLE – Aug. 20, 2020 – The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications and best practices to help ensure a secure cloud computing environment, today released Perspective on Cloud Risk Management, a new paper that looks to examine the effectiveness of governance and maturity with cloud computing risk management frameworks. The paper addresses how the underlying concepts of effective risk management can be integral to managing the broad risk introduced to enterprises by cloud computing.
“The rapid growth in both scope and market share, combined with the inherent complexity of cloud computing, is straining the capabilities of existing governance and risk management frameworks. As the users – and uses – of cloud computing evolve, so must the supporting governance models, including the maturity of governance and risk management programs,” said Daniele Catteddu, Chief Technology Officer, Cloud Security Alliance, one of the paper’s lead authors. “We hope to spur debate with this document within the cloud and risk management communities on the suitability of existing methodologies and practices.”
The document lays out five questions to stimulate discussion and facilitate possible solutions:
- Are the risk management methodologies currently available adequate to manage risks in the cloud?
- Are organizations aware of the shared responsibility model introduced by cloud computing, and are the responsibilities appropriately reflected in the risk management processes and programs?
- Are organizations aware of the concepts and implications of indirect/loss of control imposed by cloud computing and the challenges they pose to the design of risk mitigation procedures and their validation?
- Are organizations sufficiently aware of the impact that cloud computing has on the propagation of their supply chains and the difficulty in evaluating and monitoring the consolidated residual risk of third/fourth parties?
- Are the current governance practices adequate to effectively identify, evaluate and report the relevant cloud risks to relevant stakeholders?
Risk management when applied to cloud operations plays a vital role in all of an organization’s processes and is essential to its overall business improvement strategy. As such, it must be a top-level, enterprise-wide process rather than a siloed or departmental exercise. While the risk management approach is the same whether in the cloud or on-prem, there are significant differences in tactics and implementation that must be addressed. An effective risk management program will address issues related to economic value, process improvement, compliance, information security, and privacy, including:
- New operational security risks created by moving to the cloud
- Costs related to the failure to address cloud compliance
- Risks related to the cloud market growth
- Mitigation measures
CSA’s Perspective on Cloud Risk Management is a free document. Download it now.
About Cloud Security Alliance
The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, training, certification, events, and products. CSA's activities, knowledge, and extensive network benefit the entire community impacted by cloud — from providers and customers to governments, entrepreneurs, and the assurance industry — and provide a forum through which different parties can work together to create and maintain a trusted cloud ecosystem. For further information, visit us at www.cloudsecurityalliance.org, and follow us on Twitter @cloudsa.
Kari Walker for the CSA
About Cloud Security Alliance
The Cloud Security Alliance is a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing, and to provide education on the uses of Cloud Computing to help secure all other forms of computing. The Cloud Security Alliance is led by a broad coalition of industry practitioners, corporations, associations and other key stakeholders. For further information, follow us on Twitter @cloudsa.
For press inquiries, email Zenobia Godschalk of ZAG Communications or reach her by phone at 650.269.8315.