Assuring Compliance in IT Subcontracting and Cloud Computing

被引:0
|
作者
Knolmayer, Gerhard F. [1 ]
Asprion, Petra [1 ]
机构
[1] Univ Bern, Inst Informat Syst, CH-3012 Bern, Switzerland
关键词
Outsourcing; Compliance; Frameworks; Audit; Subcontracting; Cloud Computing;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Companies and their business processes are subject to many regulations. Today's business processes are widely supported by IT systems. Therefore these systems play an important role in assuring compliance. The need to assure compliance can influence IT outsourcing decisions. We summarize some frameworks that give recommendations on assuring compliance of outsourced activities. For a service provider with many globally acting customers similar audit activities of many auditors would be time-consuming and expensive. To avoid these costs, the American Institute of Certified Public Accountants (AICPA) suggested that an auditor may provide a SAS 70 Audit Report Type II which confirms the existence and effectiveness of internal controls. Recently, the AICPA replaced the SAS 70 with the attestation standard SSAE 16. Based on frameworks and guidelines we discuss compliance issues in special cases of outsourcing relationships such as Subcontracting and Cloud Computing.
引用
收藏
页码:21 / 45
页数:25
相关论文
共 50 条
  • [31] CLASS: Cloud Log Assuring Soundness and Secrecy Scheme for Cloud Forensics
    Ahsan, M. A. Manazir
    Wahab, Ainuddin Wahid Bin Abdul
    Bin Idris, Mohd Yamani Idna
    Khan, Suleman
    Bachura, Eric
    Choo, Kim-Kwang Raymond
    IEEE TRANSACTIONS ON SUSTAINABLE COMPUTING, 2021, 6 (02): : 184 - 196
  • [32] An improved forensic-by-design framework for cloud computing with systems engineering standard compliance
    Akilal, Abdellah
    Kechadi, M-Tahar
    FORENSIC SCIENCE INTERNATIONAL-DIGITAL INVESTIGATION, 2022, 40
  • [33] Adaptive workload management in cloud computing for service level agreements compliance and resource optimization
    Ghandour, Oumaima
    El Kafhali, Said
    Hanini, Mohamed
    COMPUTERS & ELECTRICAL ENGINEERING, 2024, 120
  • [34] Assuring Dependable Cloud-Based System Engineering: A Cloud Accountability Method
    Adjepon-Yamoah, David Ebo
    Wen, Zhenyu
    2016 12TH EUROPEAN DEPENDABLE COMPUTING CONFERENCE (EDCC 2016), 2016, : 181 - 184
  • [35] Cloud Computing and Information Policy: Computing in a Policy Cloud?
    Jaeger, Paul T.
    Lin, Jimmy
    Grimes, Justin M.
    JOURNAL OF INFORMATION TECHNOLOGY & POLITICS, 2008, 5 (03) : 269 - 283
  • [36] A Framework for Assuring the Conformance of Cloud-based Email
    Willett, Melanie
    Von Solms, Rossouw
    2013 8TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2013, : 168 - 173
  • [37] CLOUD COMPUTING
    Cui Yong
    Buyya, Rajkumar
    Liu Jiangchuan
    CHINA COMMUNICATIONS, 2014, 11 (04) : I - II
  • [39] CLOUD COMPUTING
    Cass, Stephen
    TECHNOLOGY REVIEW, 2009, 112 (04) : 53 - 54
  • [40] CLOUD COMPUTING
    Vankova, Lucie
    HRADECKE EKONOMICKE DNY 2011, DIL I: EKONOMICKY ROZVOJ A MANAGEMENT REGIONU. ECONOMIC DEVELOPMENT AND MANAGEMENT OF REGIONS, 2011, : 383 - 386