Analyze the degree to which auditing tools and procedures us
Analyze the degree to which auditing tools and procedures used in cloud computing (especially with respect to the public model) produce trustworthy audits?
Solution
Definition:-
It is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.
The audit and assurance professionals are expected to customize this document to the environment in which they are performing an assurance process. This document is to be used as a review tool and starting point. It may be modified by the IT audit and assurance professional.
Audits typically fall into two main categories:
1. Internal
2. External
Internal audits refer to work done by an organization’s own employees, concern very specific organizational processes, and focus primarily on optimization and risk management.
External audits give an outside perspective on an organization’s ability to meet the requirements of various laws and regulations. Organizations have used traditional IT audits to evaluate issues such as availability to authorized users and integrity and confidentiality in data storage and transmission.
Commonly define cloud service models are;-
Platform (Paas) :- Platform as a Service (PaaS) is preferred by large enterprises that need resources to develop and test new applications.
Software (Saas) :- Software as a Service (SaaS) is preferred by small and medium-sized businesses (SMEs) that see value in a use-per-pay model for applications
Infrastructure (Iaas) :- Infrastructure as a Service (IaaS) is a self-service model. Clients can choose what they prefer based on consumption and do not have to purchase hardware outright
Private and hybrid :- Private and hybrid systems are the preferred deployment models for large enterprises that need to integrate existing technology with cloud products, or that may have legal
