The report recommends how to organize and implement governance for security and compliance when using cloud services, recognizing that many organizations already use more cloud services than they realize—sometimes strategically for business transformation and customer-facing improvements, sometimes to cut costs for commodity IT like email and CRM, and sometimes informally by employees trying to “get the job done.” Moving services to the cloud shifts control of infrastructure and service delivery to the Cloud Service Provider (CSP), reshaping risk and compliance; responsibility becomes shared, yet the customer remains responsible for the security and compliance of the data processed in cloud services.
Cloud offerings span layered models— IaaS, PaaS, SaaS, and BPaaS—plus adjacent cloud-delivered IT management services such as IDaaS, and can be deployed via public, private, community, or hybrid models. Risk is grouped into four principal categories: compliance, business continuity, data security, and cyber security, with loss of compliance identified as the most prominent organizational concern. The report highlights continuity threats such as provider lock-in, unclear data ownership and return conditions, proprietary PaaS architectures, acquisitions, outsourcing chains, and end-to-end dependencies on power, communications, and availability.
A governance-led approach, with board-level sponsorship, should define cloud business objectives, policies, constraints, and risk appetite, and implement managed processes for acquisition, security controls, and ongoing assurance. Organizational readiness depends on mature IT governance (e.g., COBIT), data/app classification, standard security controls (e.g., ISO/IEC 27001), service request processes, and audit capabilities. Procurement must be fast and user-friendly to prevent bypass by lines of business, incorporate risk assessment, clarify shared responsibilities, define measurable SLAs, and require independent evidence (e.g., ISO 27001/27017/27018, SOC, CSA STAR). CASBs are recommended to improve visibility, detect unsanctioned use, and enforce policy. Finally, successful cloud management requires a named leader—often best placed in IT services—to coordinate stakeholders and drive progress toward the Future IT Paradigm.
See All Locations
See All Locations