ISACA Introduces New Google Cloud Platform Audit Program
As organisations continue to shift business operations to hybrid, single cloud or multi-cloud environments, itโ€™s important for auditors to assess risk across different deployment models and platforms.
Posted: Monday, Jul 31
  • KBI.Media
  • $
  • ISACA Introduces New Google Cloud Platform Audit Program
ISACA Introduces New Google Cloud Platform Audit Program

Sydney, Australia (31 July 2023) โ€“ As organisations continue to shift business operations to hybrid, single cloud or multi-cloud environments, itโ€™s important for auditors to assess risk across different deployment models and platforms. ISACAโ€™s new Google Cloud Platform Audit Program assists auditors understand the uniqueness of the Google Cloud Platform (GCP) while effectively assessing an enterprise cloud environment for adherence to organisational risk and compliance objectives.

 

ISACAโ€™sย Google Cloud Platform Audit Programย includes a spreadsheet file for guidance on testing GCP services and covers the following areas:ย 

 

  • Governanceย 
  • Network configuration and managementย 
  • Resource configuration and managementย 
  • Data security and integrityย 
  • Security incident responseย 
  • Business continuity and resiliency
  • Security logging and monitoring
  • Identity and access management

 

The audit program notes that as enterprises tailor and scale services to meet the needs of their operations, one of the most significant areas of risk within a cloud environment is the prevalence of misconfigurations and misunderstandings about shared cloud responsibilities. Particularly, for the GCP, auditors need to understand:

 

  • Concepts around identity and access management
  • The Organisation/Project/Folder structure
  • The impacts of inheritance and hierarchy on access and permissions
  • The enablement/disablement of logging options

 

Without a solid understanding of these, there is an increased likelihood that risk goes undetected until an incident occurs.

 

โ€œWith Google Cloud Platform now being the third-largest provider of cloud services, auditors need to make sure they have the necessary tools to assess the adequacy and effectiveness of the platform,โ€ says Robin Lyons, IT Audit Professional Practices Principal at ISACA. โ€œISACAโ€™s new audit program provides this support to audit professionals, allowing auditors to understand the types of services the GCP provides, the terminology it uses, and the enhancements and innovations offered.โ€

 

The audit program can be accessed atย  www.isaca.org/google-cloud-platform-audit-program.ย 

 

ย 

About ISACA

ISACAยฎ (www.isaca.org) is a global community advancing individuals and organisations in their pursuit of digital trust. For more than 50 years, ISACA has equipped individuals and enterprises with the knowledge, credentials, education, training and community to progress their careers, transform their organisations, and build a more trusted and ethical digital world. ISACA is a global professional association and learning organisation that leverages the expertise of its 170,000 members who work in digital trust fields such as information security, governance, assurance, risk, privacy and quality. It has a presence in 188 countries, including 225 chapters worldwide. Through its foundation One In Tech, ISACA supports IT education and career pathways for under-resourced and underrepresented populations.

Twitter: www.twitter.com/ISACANewsย ย 

LinkedIn: www.linkedin.com/company/isaca

Facebook:ย www.facebook.com/ISACAGlobalย 

Instagram: www.instagram.com/isacanews/ย 

 

Contact:

Karen Keech karen@establishedpr.com.auย  0411 052 408

Share This