30 Aug IT Auditor’s Advice
Cloud computing is a new and old model for consolidating computer systems. While it has many advantages, it also has several issues. The NIST Publication SP 800-144 describes key security and privacy issues.
IT auditors are often sought out by management as trusted advisors outside of standard audit engagements. It is not uncommon for IT auditors to carve out 10% or more of their time for non-audit consulting work.
For each of the seven named issues in section 4 of the Special Publication, discuss how you as an IT auditor would work with the Director of Information Technology at your organization to ensure that the risks associated with each issue are addressed. Remember that as an auditor, you must maintain your independence. You can advise management, but you cannot implement controls yourself.
