2015 48th Hawaii International Conference on System Sciences 2015
DOI: 10.1109/hicss.2015.629
|View full text |Cite
|
Sign up to set email alerts
|

What is Really Going On at Your Cloud Service Provider? Creating Trustworthy Certifications by Continuous Auditing

Abstract: Cloud service certifications attempt to assure a high level of security and compliance. However, considering that cloud services are part of an everchanging environment, multi-year validity periods may put in doubt the reliability of such certifications. We argue that continuous auditing of selected certification criteria is required to assure continuously reliable and secure cloud services and thereby increase the trustworthiness of certifications. Continuous auditing of cloud services is still in its infancy… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1

Citation Types

0
3
0

Year Published

2020
2020
2024
2024

Publication Types

Select...
5
3

Relationship

0
8

Authors

Journals

citations
Cited by 20 publications
(3 citation statements)
references
References 44 publications
(122 reference statements)
0
3
0
Order By: Relevance
“…Furthermore, the use of automation in auditing is not without challenges. While automation can improve efficiency, there are limitations in automating industry-specific auditing processes due to high customization costs (Lins et al, 2015). Additionally, the adoption of automation in auditing may require auditors to embrace new competencies and workflows to effectively utilize these technologies ("Implementation of Robotic Process Automation: Audit Process, Workflow, and Competencies In Indonesian Banking Firms", n.d.).…”
Section: Results and Discussion A Automation And Workforce Supplement...mentioning
confidence: 99%
“…Furthermore, the use of automation in auditing is not without challenges. While automation can improve efficiency, there are limitations in automating industry-specific auditing processes due to high customization costs (Lins et al, 2015). Additionally, the adoption of automation in auditing may require auditors to embrace new competencies and workflows to effectively utilize these technologies ("Implementation of Robotic Process Automation: Audit Process, Workflow, and Competencies In Indonesian Banking Firms", n.d.).…”
Section: Results and Discussion A Automation And Workforce Supplement...mentioning
confidence: 99%
“…However, most existing public auditing schemes could not resist a procrastinating auditor. Usually, the agreed frequency of data integrity check is weekly, monthly, or quarterly [16][17] which is not high, due to the cost issue and the burden on the CS side. An honest auditor would perform the check as scheduled, however, a procrastinating auditor may not conduct the auditing task timely until the last second.…”
Section: On the Vulnerability Of Procrastinating Auditorsmentioning
confidence: 99%
“…The topic has already been addressed in different contexts for some years from a general auditing perspective, but more in research than in practical implementations. For example in research articles 5 7 , but also in other certification schemes, such as the CSA STAR, which includes a continuous assessment aspect in level 3 assessments. In terms of already existing tools, many hyperscalers and technology providers offer security compliance monitoring tools, but they might not provide an auditor interface, since their preferred use case is as an internal monitoring tool.…”
Section: Introductionmentioning
confidence: 99%