Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cloud Security

Cloud Security Alliance Unveils Governance, Risk Management and Compliance Stack

Governance, Risk Management and Compliance Stack Provides Toolkit for Key Stakeholders to Implement and Assess Security of Cloud Environments

Today at the CSA Congress in Orlando, Florida, The Cloud Security Alliance (CSA) announced the availability of its Governance, Risk Management and Compliance (GRC) Stack, an integrated suite of initiative for GRC in the cloud.

Governance, Risk Management and Compliance Stack Provides Toolkit for Key Stakeholders to Implement and Assess Security of Cloud Environments

Today at the CSA Congress in Orlando, Florida, The Cloud Security Alliance (CSA) announced the availability of its Governance, Risk Management and Compliance (GRC) Stack, an integrated suite of initiative for GRC in the cloud.

The GRC Stack from the Cloud Security Alliance provides a toolkit for enterprises, cloud providers, security solution providers, IT auditors and other key stakeholders to instrument and assess both private and public clouds against industry established best practices, standards and critical compliance requirements.Cloud Security Alliance GRC Stack

Achieving GRC goals requires appropriate assessment criteria, relevant control objectives and timely access to necessary supporting data. Whether implementing private, public or hybrid clouds, the shift to compute-as-a-service presents new challenges across the spectrum of GRC requirements.

Despite significant progress in compliance and security programs within organizations, a new era is upon us with heightened compliance obligations, and organizations that don’t have the proper security controls will have to catch up quickly. “When cloud computing is treated as a governance initiative, with broad stakeholder engagement and well-planned risk management activities, it can bring tremendous value to an enterprise,” said Emil D’Angelo, CISA, CISM, international president of ISACA, a founding member of the Cloud Security Alliance and a co-developer of the GRC stack.

“Gaining visibility into service provider environments and governing them according to overall enterprise GRC strategy have emerged as major concerns for organizations when considering the use of public cloud services,” said Eric Baize, Senior Director of Cloud Security Strategy at RSA, The Security Division of EMC.

The stack is integrates three CSA initiatives: CloudAudit, Cloud Controls Matrix and Consensus Assessments Initiative Questionnaire.

• CloudAudit: aims to provide a common interface and namespace that allows cloud computing providers to automate the Audit, Assertion, Assessment, and Assurance (A6) of their infrastructure (IaaS), platform (PaaS), and application (SaaS) environments and allow authorized consumers of their services to do likewise via an open, extensible and secure interface and methodology. CloudAudit provides the technical foundation to enable transparency and trust in private and public cloud systems.

• Cloud Controls Matrix (CCM): provides a controls framework that gives detailed understanding of security concepts and principles that are aligned to the Cloud Security Alliance guidance in 13 domains. As a framework, the CSA CCM provides organizations with the needed structure, detail and clarity relating to information security tailored to the cloud industry.

Advertisement. Scroll to continue reading.

• Consensus Assessments Initiative Questionnaire (CAIQ): The CSA Consensus Assessments Initiative (CAI) performs research, creates tools and creates industry partnerships to enable cloud computing assessments. The CAIQ provides industry-accepted ways to document what security controls exist in IaaS, PaaS, and SaaS offerings, providing security control transparency. The questionnaire (CAIQ) provides a set of questions a cloud consumer and cloud auditor may wish to ask of a cloud provider.

Subscribe to SecurityWeek

“Cloud computing brings tremendous benefits to business, but these models also raise questions around compliance and shared responsibility for data protection,” said Scott Charney, Corporate Vice President for Microsoft’s Trustworthy Computing Group. “With the Cloud Security Alliance’s guidance, providers and enterprises can use a common language to ensure the right security issues are being considered and addressed for each type of cloud environment.”

The three initiatives have been developed through a collaborative effort and contain out-of-the-box integration. CloudAudit includes the Cloud Controls Matrix as an included namespace, while the Consensus Assessments Initiative Questionnaire was specifically designed to identify the presence or lack of CCM controls and other key practices identified in the CSA guidance.

“The Cloud Security Alliance GRC Stack is a major step allowing Cloud Computing vendors to document to their subscribers the level of Security and Compliance they maintain,” said Philippe Courtot, chairman and CEO of Qualys. “As Cloud Computing is rapidly changing the way we do business, such a framework is essential to ensuring that our data is secure and that Cloud Computing vendors adhere to privacy and regulatory requirements.”

The Cloud Security Alliance GRC stack can be found at: http://www.cloudsecurityalliance.org/grcstack

The Cloud Security Alliance is a not-for-profit organization working to promote the use of best practices for providing security assurance within Cloud Computing, and to provide education on the uses of Cloud Computing to help secure all other forms of computing.

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

Shaun Khalfan has joined payments giant PayPal as SVP, CISO.

UK cybersecurity agency NCSC announced Richard Horne as its new CEO.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

CISO Conversations

SecurityWeek talks to Billy Spears, CISO at Teradata (a multi-cloud analytics provider), and Lea Kissner, CISO at cloud security firm Lacework.

Cloud Security

Cloud security researcher warns that stolen Microsoft signing key was more powerful and not limited to Outlook.com and Exchange Online.

CISO Strategy

Okta is blaming the recent hack of its support system on an employee who logged into a personal Google account on a company-managed laptop.

Cybersecurity Funding

2022 Cybersecurity Year in Review: Top news headlines and trends that impacted the security ecosystem

Endpoint Security

Today, on January 10, 2023, Windows 7 Extended Security Updates (ESU) and Windows 8.1 have reached their end of support dates.

Compliance

The three primary drivers for cyber regulations are voter privacy, the economy, and national security – with the complication that the first is often...