• Fri frakt över 249 kr
  • •
  • Snabba leveranser
  • •
  • Billiga böcker
Kundservice

Du är på sajten för privatpersoner.

Företag, bibliotek eller offentlig verksamhet?

Du handlar på classic.bokus.com, där alla dina funktioner finns intakta.
Till classic.bokus.com
Bokus logotyp. Gå till startsidan.
  • Erbjudanden
  • Nyheter
  • Student
  • Topplistor
  • Barn & ungdom
  • Bokus Play
  • E-böcker
  • Pocketböcker
  • Spel & pussel

10% rabatt på allt med kod NYSTART10 →

Sidfot

Mina sidor

    Hjälp

    • Kundservice
    • Vanliga frågor och svar
    • Frakt och leverans
    • Retur vid ångerrätt
    • Reklamera vara
    • Betalning
    • Köpvillkor
    • Allmänna villkor
    • Information om webbplatsens tillgänglighet

    Om Bokus

    • Om oss
    • Pressrum
    • För studenter
    • För företag
    • För bibliotek och offentlig verksamhet
    • För leverantörer
    • Hållbarhet

    Populärt

    • Aktuella erbjudanden
    • Presentkort
    • Studentlitteratur
    • Nya böcker
    • Topplistor
    • Signerade böcker
    • Engelska böcker

    Inspiration

    • Boktips
    • BookTok
    • Populära bokserier
    • Barnbokskaraktärer
    • Populära författare
    Logotyp för Bokus
    Följ oss på Facebook (extern länk)Följ oss på Instagram (extern länk)Följ oss på YouTube (extern länk)Följ oss på TikTok (extern länk)
    bokus @ CookiesAnpassa cookiesIntegritetspolicyKöpvillkor
    Till Citymail hemsida (extern länk)Till Budbee hemsida (extern länk)Till Postnord hemsida (extern länk)Till Schenker hemsida (extern länk)Till Early Bird hemsida (extern länk)Till Walleys hemsida (extern länk)
    1. Data och IT
    2. Nätverk och kommunikation

    Auditing Cloud Computing

    A Security and Privacy Guide

    AvBen Halpert

    Inbunden, Engelska, 2011

    Del 21 i serien Wiley Corporate F&A

    474 kr

    Beställningsvara. Skickas inom 5-8 vardagar. Fri frakt över 249 kr.

    Fler format och utgåvor

    E-bok

    610 kr

    E-bok

    610 kr

    Beskrivning

    The auditor's guide to ensuring correct security and privacy practices in a cloud computing environment Many organizations are reporting or projecting a significant cost savings through the use of cloud computing—utilizing shared computing resources to provide ubiquitous access for organizations and end users. Just as many organizations, however, are expressing concern with security and privacy issues for their organization's data in the "cloud." Auditing Cloud Computing provides necessary guidance to build a proper audit to ensure operational integrity and customer data protection, among other aspects, are addressed for cloud based resources. Provides necessary guidance to ensure auditors address security and privacy aspects that through a proper audit can provide a specified level of assurance for an organization's resourcesReveals effective methods for evaluating the security and privacy practices of cloud servicesA cloud computing reference for auditors and IT security professionals, as well as those preparing for certification credentials, such as Certified Information Systems Auditor (CISA)Timely and practical, Auditing Cloud Computing expertly provides information to assist in preparing for an audit addressing cloud computing security and privacy for both businesses and cloud based service providers.

    Produktinformation

    • Utgivningsdatum:2011-08-26
    • Mått:160 x 236 x 21 mm
    • Vikt:399 g
    • Format:Inbunden
    • Språk:Engelska
    • Serie:Wiley Corporate F&A
    • Antal sidor:224
    • Förlag:John Wiley & Sons Inc
    • ISBN:9780470874745

    Utforska kategorier

    • Nätverk och kommunikation inom Data och IT
    • Affärsförhandlingar inom Ekonomi och Ledarskap
    • IT-säkerhet inom Data och IT

    Mer om författaren

    BEN HALPERT, CISSP, is an information security researcher and practitioner. He has keynoted and presented sessions at numerous conferences and was a contributing author to Readings and Cases in the Management of Information Security and the Encyclopedia of Information Ethics and Security. Halpert writes a monthly security column for Mobile Enterprise magazine as well as an IT blog (www.benhalpert.com). He is also an adjunct instructor and on the advisory board of numerous colleges and universities.

    Recensioner i media

    "To summarize, the book is a good review of the current situation in the field. Every CISO and CIO should be aware of the developments in the cloud regardless of the intention of actually implementing its use." (Blog.itgovernance.co.uk, April 2012)

    Innehållsförteckning

    • Preface xiii Chapter 1: Introduction to Cloud Computing 1History 1Defining Cloud Computing 2Elasticity 2Multitenancy 3Economics 3Abstraction 3Cloud Computing Services Layers 4Infrastructure as a Service 5Platform as a Service 5Software as a Service 6Roles in Cloud Computing 6Consumer 6Provider 6Integrator 7Cloud Computing Deployment Models 8Private 8Community 8Public 9Hybrid 9Challenges 9Availability 10Data Residency 10Multitenancy 11Performance 11Data Evacuation 12Supervisory Access 12In Summary 13Chapter 2: Cloud-Based IT Audit Process 15The Audit Process 16Control Frameworks for the Cloud 18ENISA Cloud Risk Assessment 20FedRAMP 20Entities Using COBIT 21CSA Guidance 21CloudAudit/A6—The Automated Audit, Assertion, Assessment, and Assurance API 22Recommended Controls 22Risk Management and Risk Assessment 26Risk Management 27Risk Assessment 27Legal 28In Summary 29Chapter 3: Cloud-Based IT Governance 33Governance in the Cloud 36Understanding the Cloud 36Security Issues in the Cloud 37Abuse and Nefarious Use of Cloud Computing 38Insecure Application Programming Interfaces 39Malicious Insiders 39Shared Technology Vulnerabilities 39Data Loss/Leakage 40Account, Service, and Traffic Hijacking 40Unknown Risk Profile 40Other Security Issues in the Cloud 41Governance 41IT Governance in the Cloud 44Managing Service Agreements 44Implementing and Maintaining Governance for Cloud Computing 46Implementing Governance as a New Concept 46Preliminary Tasks 46Adopt a Governance Implementation Methodology 48Extending IT Governance to the Cloud 49In Summary 52Chapter 4: System and Infrastructure Lifecycle Management for the Cloud 57Every Decision Involves Making a Tradeoff 57Example: Business Continuity/Disaster Recovery 59What about Policy and Process Collisions? 60The System and Management Lifecycle Onion 61Mapping Control Methodologies onto the Cloud 62Information Technology Infrastructure Library 63Control Objectives for Information and Related Technology 64National Institute of Standards and Technology 65Cloud Security Alliance 66Verifying Your Lifecycle Management 67Always Start with Compliance Governance 67Verification Method 68Illustrative Example 70Risk Tolerance 72Special Considerations for Cross-Cloud Deployments 73The Cloud Provider’s Perspective 74Questions That Matter 75In Summary 76Chapter 5: Cloud-Based IT Service Delivery and Support 79Beyond Mere Migration 80Architected to Share, Securely 80Single-Tenant Offsite Operations (Managed Service Providers) 81Isolated-Tenant Application Services (Application Service Providers) 81Multitenant (Cloud) Applications and Platforms 82Granular Privilege Assignment 82Inherent Transaction Visibility 84Centralized Community Creation 86Coherent Customization 88The Question of Location 90Designed and Delivered for Trust 91Fewer Points of Failure 91Visibility and Transparency 93In Summary 93Chapter 6: Protection and Privacy of Information Assets in the Cloud 97The Three Usage Scenarios 99What Is a Cloud? Establishing the Context—Defining Cloud Solutions and their Characteristics 100What Makes a Cloud Solution? 101Understanding the Characteristics 104Service Based 104On-Demand Self-Service 104Broad Network Access 104Scalable and Elastic 105Unpredictable Demand 105Demand Servicing 105Resource Pooling 105Managed Shared Service 105Auditability 105Service Termination and Rollback 106Charge by Quality of Service and Use 106Capability to Monitor and Quantify Use 106Monitor and Enforce Service Policies 107Compensation for Location Independence 107Multitenancy 107Authentication and Authorization 108Confidentiality 108Integrity 108Authenticity 108Availability 108Accounting and Control 109Collaboration Oriented Architecture 109Federated Access and ID Management 109The Cloud Security Continuum and a Cloud Security Reference Model 110Cloud Characteristics, Data Classification, and Information Lifecycle Management 113Cloud Characteristics and Privacy and the Protection of Information Assets 113Information Asset Lifecycle and Cloud Models 114Data Privacy in the Cloud 118Data Classification in the Context of the Cloud 119Regulatory and Compliance Implications 119A Cloud Information Asset Protection and Privacy Playbook 121In Summary 124Chapter 7: Business Continuity and Disaster Recovery 129Business Continuity Planning and Disaster Recovery Planning Overview 129Problem Statement 130The Planning Process 131The Auditor’s Role 133Augmenting Traditional Disaster Recovery with Cloud Services 135Cloud Computing and Disaster Recovery: New Issues to Consider 136Cloud Computing Continuity 136Audit Points to Emphasize 138In Summary 139Chapter 8: Global Regulation and Cloud Computing 143What is Regulation? 144Federal Information Security Management Act 146Sarbanes-Oxley Law 146Health Information Privacy Accountability Act 146Graham/Leach/Bliley Act 147Privacy Laws 147Why Do Regulations Occur? 148Some Key Takeaways 149The Real World—A Mixing Bowl 149Some Key Takeaways 151The Regulation Story 151Privacy 153International Export Law and Interoperable Compliance 154Effective Audit 155Identifying Risk 156In Summary 156Chapter 9: Cloud Morphing: Shaping the Future of Cloud Computing Security and Audit 161Where Is the Data? 162A Shift in Thinking 164Cloud Security Alliance 165CloudAudit 1.0 166Cloud Morphing Strategies 166Virtual Security 167Data in the Cloud 168Cloud Storage 169Database Classes in the Cloud 171Perimeter Security 171Cryptographic Protection of the Data 172In Summary 173Appendix: Cloud Computing Audit Checklist 175About the Editor 181About the Contributors 183Index 191