EnterpriseGRC Solutions has invested substantial time in readdressing our Cloud Security Assessment methodology. A lot of our resources were released as far back as 2011 to 2015, which means they are not sufficiently aligned with Zero Trust. Even the work contributed to mapping NIST SP 800-53 rev 5 and CMMC 2.0 during 2021 and 2022 lack specificity in ZTA. The CCM 4.5 clearly points to the use of ZTA, but we're leaning forward in the saddle to define new processes and procedures and then, in turn, to work with our community to suggest new control languages, and to encourage everyone to immediately implement the best and most critical new resources.
It's a journey, not a destination.

We recently added to our capabilities with the Information technology — Cloud computing — Audit of cloud services ISO/IEC TR 3445:2022(E). Let's begin again by asking if we and our clients have sufficiently prepared their Cloud plus Zero Trust Architecture business use case?
In preparing the business case for adopting a cloud strategy, organizations’ internal audit must be able to assess the following:
- Regulatory compliance: assess the CSPs’ approach to meeting the regulatory requirements with which the organization has to comply.
- Data location and ownership: assess whether the location of CSP's data storage and processing meets the required jurisdictional conditions.
- Business viability and recovery: assess the confidence of getting the organization’s data if and when the CSPs lose their business and the impact on recovery capabilities.
- Colocation and data segregation: assess the physical location of data storage and assurance of data server and separation of the organization’s data.
- Systems and data: assess the sensitivity and adaptability of the organization’s data considered for possible use in the cloud environment.
- Organization’s risks and controls: assess CSPs that best align with the organization’s controls and evaluate how best to address any gaps.
- Roles and responsibilities: determine the roles and responsibilities of both the organization and CSPs in ensuring the use of the cloud services.
- Assessment of application: determine the suitability of legacy or non-cloud systems viability for cloud migration and applicability for use with cloud services.
- Assessment of applications for migration: non-cloud to private cloud, non-cloud to the public cloud, private cloud to public cloud, and private cloud to public cloud.
- Privileged user access: assess CSP's control and assurance of access to the organization's data.
How we responded
- We completed a full reconciliation to determine where CSF 1.1 and Privacy framework support Cloud and Zero Trust environments and collaborated to establish an inventory the gaps in CSF 1.1 as compared to CCM 4.5 and to planned future additions to that standard.
- We confirmed and extended our existing mapping ISO/IEC 27017 Cloud Certification to CSF 1.1 to determine alignment in the existing policy framework and to identify 32+ specific cloud requirements for confirmation or added implementation in a Cloudified and Zero Trust assessment
- As a mechanism to design a phased approach, we applied a “Client as Consumer” paradigm to limit the depth of controls across IaaS and PaaS. Retain risks related to dependency on SaaS and their supporting environments (public, private or hybrid), and endpoint controls b/c these support those SaaS services.
- Put priority on threats affecting browsers and laptops (UEM/TVM) that connect to SaaS, and Application constraints (AIS) that prevent loading insecure content.
- Architecture:
- For every GRC system we are asked to interact with we make sure it has all necessary the new fields and array of selections necessary to cloudify existing questions.
- Listing an array of common nonconformance statements to assist clients in assessing their cloud risk appetite and posture.
We re-address the ISF Risk Model, return again to the ENISA Risk Model, apply again the ISO/IEC Cloud Guidance from the 27017 Cloud Certification, and examine deeper aspects of the NIST SP 800-53 rev 5, especially concerning the next release of FedRAMP defined Selection Parameters.
Risks associated with Improper Implementation of Cloud – adapted from ISF
|
Expected Outcome Importance |
Problem Behavior |
Add these terms to Problem / Importance of doing it right |
|
Cloud implementations are managed consistently and systematically in the organization |
Ignorance |
Cloud is already being used without management knowledge and approval |
|
The organization does not enter into contracts unless there’s a clear understanding of the risks |
Ambiguity |
The organization assigns contracts with insufficient attention given to risk management |
|
Information is protected by the cloud supplier and the organization has the right to audit what they are doing |
Doubt |
Little or no assurance regarding the management of the organization’s information is provided by or is available from cloud suppliers. |
|
The organization is compliant with all relevant laws and regulations |
Trespass |
Information gets into the cloud that breaks laws and / or regulations |
|
Information is classified and the classification used to define appropriate controls |
Disorder |
Information is not protected at each stage of its lifecycle |
|
Proven, standard approaches are used to access, process and update information stored in the cloud |
Immaturity or deceit |
No standards infrastructure is in place in the organization to guarantee secure use of the cloud, leading to information leakage |
|
Information and systems are available when needed |
Complacency |
Availability is assumed, but outages happen and cost real money |
The Continuous Audit Metrics Working Group is https://cloudsecurityalliance.org/research/working-groups/continuous-audit-metrics/
Expanding the Shared Responsibility model
Cloud Security Technical Reference Architecture - CISA and USDS, Federal Risk Authorization Management (read more)
How might our customers already be using Cloud?
- On-demand self-service: A consumer can unilaterally provision computing capabilities, such as server time and network storage, as needed automatically without requiring human interaction with each service’s provider.
- Broad network access: Capabilities are available over the network and accessed through standard mechanisms that promote use by heterogeneous thin or thick client platforms (e.g., cell phones, laptops, and PDAs).
- Resource pooling: The provider’s computing resources are pooled to serve multiple consumers using a multi-tenant model, with different physical and virtual resources dynamically assigned and reassigned according to consumer demand. There is a sense of location independence in that the customer generally has no control or knowledge over the exact location of the provided resources but may be able to specify location at a higher level of abstraction (e.g., country, state, or datacenter). Examples of resources include storage, processing, memory, network bandwidth, and virtual machines.
- Rapid elasticity: Capabilities can be rapidly and elastically provisioned, in some cases automatically, to quickly scale out, and rapidly released to quickly scale in. To the consumer, the capabilities available for provisioning often appear to be unlimited and can be purchased in any quantity at any time.
- Measured Service: Cloud systems automatically control and optimize resource use by leveraging a metering capability at some level of abstraction appropriate to the type of service (e.g., storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, and reported, providing transparency for both the provider and consumer of the utilized service.
Exploring current models for the division of responsibilities:
SOFTWARE AS A SERVICE
|
Customer |
Provider |
|
|
PLATFORM AS A SERVICE
|
Customer |
Provider |
|
|
INFRASTRUCTURE AS A SERVICE
|
Customer |
Provider |
|
|
Identify where we and our client rely on Cloud Service Models
Where do you currently leverage cloud services?
NIST Cloud Computing Reference Architecture (read more)
SaaS
- ERP*
- Human Resources *
- Social Network ***
- Financials*
- Content Management
- Email & Office Productivity
- Document Management
- Collaboration
- CRM
- Sales
- Billing
PaaS
- Database
- Application Deployment
- Integration**
- Development & Testing
- Business Intelligence
IaaS**
- Storage
- CDN
- Backup & Recovery
- Services Management
- Platform Hosting
- Compute
* If HR, ERP, and Financial systems are in the cloud there should be a SOC 2 and a SOX assessment associated with their controls.
** Integration and portions of IaaS may fall outside of the customer’s shared responsibility model. If they are using a Public Cloud, our questions may consistently result in the same risk finding. “Uncontrolled purchasing of cloud services; Failure to detect the use of new cloud services; Cloud services implemented without sufficiently addressing security requirements”
***Social Networking Policy - this is a longer topic.
Business Concerns
Interview topics that result in statements involving the Client’s capacity to either benefit from or their inability to benefit from the use of cloud technologies and services.
Cost
- including capital cost for servers, storage, network, software, and so on, and the operational cost involved in running the IT systems consumes a large portion of a business budget.
Maintenance
- current applications not only involves money and time, but also quite a bit of management attention.
Security and Risk Management
- regulatory and legal reasons and for business continuity
User Experience
- determines the enthusiasm with which applications will be integrated in the day-to-day business
Flexibility
- Businesses expands and contracts. For most organizations, the flexibility of IT plays a crucial role in facilitating growth.
Expansion
- IT systems continue to expand beyond the physical borders of the organization


|
Attribute Value |
Attribute Label |
Description |
|
SaaS |
Software as a Service |
SaaS is the capability provided to the consumer is to use the provider’s applications running on a cloud infrastructure; the applications are accessible from various client devices through a thin client interface. such as a Web browser (for example, Web-based e-mail); the consumer does not manage or control the underlying cloud infrastructure, including network, servers, operating systems, storage, or even individual application capabilities, except for limited user-specific application configuration settings |
|
PaaS |
Platform as a Service |
PaaS is the capability provided to the consumer is to deploy onto the cloud infrastructure consumer-created or acquired applications created using programming languages and tools supported by the provider. The consumer does not manage or control the underlying cloud infrastructure including network, servers, operating systems, or storage, but has control over the deployed applications and possibly application hosting environment configurations. |
|
IaaS |
Infrastructure as a Service |
IaaS is the capability provided to the consumer to provision processing, storage, networks, and other fundamental computing resources where the consumer can deploy and run arbitrary software, which can include operating systems and applications; the consumer does not manage or control the underlying cloud infrastructure but has control over operating systems, storage, deployed applications, and possibly limited control over select networking components (for example, host firewalls) |
|
SaaS; PaaS; |
Combination |
Software services and the platform used to serve and install them. |
|
PaaS; IaaS; |
Combination |
Platform services and the infrastructure used to deploy and implement them. |
|
SaaS; PaaS; IaaS; |
Combination |
Services, the services delivery platform, and the infrastructure used to deploy and maintain them. This should include SRO and SQO. |
|
CaaS |
Communications as a Service |
Communications as a Service (CaaS) is an outsourced enterprise communications solution that can be leased from a single vendor. Such communications can include voice over IP (VoIP or Internet telephony), instant messaging (IM), collaboration and videoconference applications using fixed and mobile devices. CaaS has evolved along the same lines as Software as a Service (SaaS). Also note this may be used to mean Container as a Service |
|
CompaaS* |
Compute as a Service |
Compute as a Service Compliance as a Service (I'd love to invite a speaker to ISC2 East Bay to speak definitively about CaaS v. CompaaS. |
|
DSaaS |
Data Storage as a Service |
Storage as a service (STaaS) is a data storage business model where a provider rents storage resources to a customer through a subscription. STaaS saves you money through operating expenditure (OpEx) agility (Side note, I plan to have Purestorage as a future speaker at ISC2 East Bay.) |
Cloud Deployment
|
Attribute Value |
Attribute Label |
Description via popup |
|
Private cloud |
Private cloud |
The cloud infrastructure is operated solely for an organization. |
|
Community cloud |
Community cloud |
The cloud infrastructure is shared by several organizations and supports a specific community that has shared concerns (e.g., mission, security requirements, policy, and compliance considerations). |
|
Public cloud |
Public cloud |
The cloud infrastructure is made available to the general public or a large industry group and is owned by an organization selling cloud services. |
|
Hybrid cloud |
Hybrid cloud |
The cloud infrastructure is a composition of two or more clouds (private, community, or public) that remain unique entities but are bound together by standardized or proprietary technology that enables data and application portability (e.g., cloud bursting for load-balancing between clouds).. |
|
PRIVATE |
COMMUNITY |
PUBLIC |
|
|
ACCESSIBILITY |
Single Organization |
Shared with Common Interests / Requirements |
General Public / Large Industry Group |
|
MANAGEMENT |
Organization or Third Party |
Organization or Third Party |
Cloud Provider |
|
HOST |
On or Off Premise |
On or Off Premise |
On or Off Premise |
Virtualization Simplifies Application Development Process
Agile Development
- Agile Development, which calls for rapid, incremental delivery of new code in a running system driven by specific test cases, can be greatly streamlined by virtualization. The developer can clone an environment to hand over to testers and continue to work without having to spend time laboriously recreating environments for testing.
Multi-tier Environments
- When dealing with code that runs in different environments, as in commercial software or even when sharing an application between geographies or business units in a single company, it can be hard to replicate bugs and test whether fixes work. Virtualization can aid here in several ways:
- maintain multiple testing environments without expensive, rarely used hardware.
- Ability to keep literally all versions of the software run ready
- Virtual snapshot of a customer's running system and bring it intact into the lab for testing.
Packaging and Installation
- Conventional approaches to packaging and installation can leave customers and systems administrators with the complex task of installing the application and its dependencies and properly configuring the software. With careful planning, this kind of repetitive systems administration task can become a thing of the past as development teams deploy software as virtual appliances ready to run in a server virtualization environment. With contemporary virtualization platforms, even sophisticated multi-tier applications can be packaged and released, ready to install and go.
Defect Management
- Some software defects can be extremely hard to track down when they involve networks of application code on different machines performing unpredictably. Defects can be greatly dependent on timing, and so-called Heisenbugs can be incredibly hard to isolate. When an entire network of machines is virtualized and run on a single machine for test purposes, advanced debugging systems like Sun Microsystems' DTRACE can greatly reduce the complexity of the problem.







Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics