Assuring Compliance in IT Subcontracting and Cloud Computing

被引:0
|
作者
Knolmayer, Gerhard F. [1 ]
Asprion, Petra [1 ]
机构
[1] Univ Bern, Inst Informat Syst, CH-3012 Bern, Switzerland
关键词
Outsourcing; Compliance; Frameworks; Audit; Subcontracting; Cloud Computing;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Companies and their business processes are subject to many regulations. Today's business processes are widely supported by IT systems. Therefore these systems play an important role in assuring compliance. The need to assure compliance can influence IT outsourcing decisions. We summarize some frameworks that give recommendations on assuring compliance of outsourced activities. For a service provider with many globally acting customers similar audit activities of many auditors would be time-consuming and expensive. To avoid these costs, the American Institute of Certified Public Accountants (AICPA) suggested that an auditor may provide a SAS 70 Audit Report Type II which confirms the existence and effectiveness of internal controls. Recently, the AICPA replaced the SAS 70 with the attestation standard SSAE 16. Based on frameworks and guidelines we discuss compliance issues in special cases of outsourcing relationships such as Subcontracting and Cloud Computing.
引用
收藏
页码:21 / 45
页数:25
相关论文
共 50 条
  • [1] A survey of compliance issues in cloud computing
    Yimam, Dereje
    Fernandez, Eduardo B.
    JOURNAL OF INTERNET SERVICES AND APPLICATIONS, 2016, 7 (01)
  • [2] Data protection and legal compliance in cloud computing
    Udo Helmbrecht
    Datenschutz und Datensicherheit - DuD, 2010, 34 (8) : 554 - 556
  • [3] A Unified Framework for GDPR Compliance in Cloud Computing
    Pattakou, Argyri
    Diamantopoulou, Vasiliki
    Kalloniatis, Christos
    Gritzalis, Stefanos
    19TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY, ARES 2024, 2024,
  • [4] Data Flow Management and Compliance in Cloud Computing
    Singh, Jatinder
    Powles, Julia
    Pasquier, Thomas
    Bacon, Jean
    IEEE CLOUD COMPUTING, 2015, 2 (04): : 24 - 32
  • [5] Governance und Compliance im Cloud Computing
    Khaled Bagban
    Ricardo Nebot
    HMD Praxis der Wirtschaftsinformatik, 2014, 51 (3) : 267 - 283
  • [6] Designing a trivial information relaying scheme for assuring safety in mobile cloud computing environment
    Thillaiarasu, N.
    Pandian, S. Chenthur
    Vijayakumar, V.
    Prabaharan, S.
    Ravi, Logesh
    Subramaniyaswamy, V
    WIRELESS NETWORKS, 2021, 27 (08) : 5477 - 5490
  • [7] Designing a trivial information relaying scheme for assuring safety in mobile cloud computing environment
    N. Thillaiarasu
    S. Chenthur Pandian
    V. Vijayakumar
    S. Prabaharan
    Logesh Ravi
    V. Subramaniyaswamy
    Wireless Networks, 2021, 27 : 5477 - 5490
  • [8] A Unified Approach Toward Security Audit and Compliance in Cloud Computing
    Rajesh Y.S.
    Kumar V.G.K.
    Poojari A.
    Journal of The Institution of Engineers (India): Series B, 2024, 105 (03) : 733 - 750
  • [9] Cloud/edge computing for compliance in the Brazilian livestock supply chain
    Bergier, Ivan
    Papa, Matheus
    Silva, Roosevelt
    Santos, Patricia Menezes
    SCIENCE OF THE TOTAL ENVIRONMENT, 2021, 761 (761)
  • [10] Peers Feedback and Compliance Based Trust Computation for Cloud Computing
    Sidhu, Jagpreet
    Singh, Sarbjeet
    SECURITY IN COMPUTING AND COMMUNICATIONS, 2014, 467 : 68 - 80