Cloud Applications _and_amp; SOX Compliance 2922
-
Does anyone in the forum know of/have experience with records management software that corresponds with Google Apps AND meets SOX compliance requirements? I’d like to hear opinions of what is out there.
-
Hi and welcome to the forums …
While I’m familiar with cloud computing, SOX 404 is usually silent on specific technologies allowing companies to adopt differing technological and business solutions – as long as all financial processing is well controlled and overall security controls are good.
With that said, Cloud Computing is not truly a brand new paradigmn , as it has it roots in SaaS and earlier third party vendor hosted computing solutions. The same concerns in securing data offsite applies to Cloud Computing with strong reliances necessary by the vendor.
However, like any other financial application there must be strong controls to ensure controls are met (e.g., External SOX auditors often use COBIT for IT based controls and COSO for the overall control framework). It might be good to touch base with external auditors regarding requirements and concerns they may have.
Some great articles found in Google Search using ’ Cloud Computing Sarbanes-Oxley ’ as Search argument:
Please copy and paste links as direct links are prohibited in forums
http-and-#58;//www.complianceweek.com/article/5516/developing-a-matrix-for-cloud-computing-compliance
http-and-#58;//cloudcomputing.sys-con.com/node/1622079
http-and-#58;//itmanagement.earthweb.com/netsys/article.php/3760726/The-Many-Dangers-of-Cloud-Computing.htm
and likewise a search of Google Apps and Sarbanes-Oxley yielded a few good articles, including this one:
http-and-#58;//www.fiercecomplianceit.com/story/sarbox-an-issue-for-google-apps-adoption/2007-03-27
-
Sharing additional links for your research
Trend Labs has created a Cloud Security blog and highlights key concerns for corporate users as noted below:
Trend Labs - Is your organization ready for Cloud?
http-and-#58;//blog.trendmicro.com/is-your-organization-ready-for-the-cloud/
Trend Labs - Cloud Security Blog
http-and-#58;//cloudsecurity.trendmicro.com/
-
Thanks so much for the feedback and helpful links. Especially interesting were the blogs on corporate security and tools for evaluating whether or not a company is prepared to make the move to the cloud.
-
@harrywaldron Thanks for sharing
-
@harrywaldron Thanks for sharing | AWS Classes in Pune |