SlideShare a Scribd company logo
Session 2b, 26th
October 2011 eChallenges e-2011 Copyright 2011 SAP Research
Auditing Issues for Cloud-based
Business Services
Jonathan Sinclair
SAP Research Belfast
UK
Session 2b, 26th
October 2011 eChallenges e-2011 Copyright 2011 SAP Research
Agenda
• Fundamentals of Cloud, Compliance and Auditing
• Cloud Compliance Challenges
• Use Case: Future Healthcare and CRM
• Compliance Auditing
• Conclusions
Session 2b, 26th
October 2011 eChallenges e-2011 Copyright 2011 SAP Research
Fundamentals
Compliance
Compliance is defined as
being in accordance with
relevant governmental orindustrial laws, regulationsand standards through
governance processes.
Business Web
A business model and
technical framework that
represents a marketplace
allowing providers and
consumers to negotiate the
usage of products.
Clouds are a large pool of
easily usable and accessible
virtualized resources that
can be dynamically
reconfigured to adjust to a
variable load.
Cloud Computing
Auditing
The process of collecting and
evaluating evidence to
determine whether a
computer system (information
system) safeguards assets,
maintains data integrity,
achieves organizational goals
effectively and consumes
resources efficiently.
Session 2b, 26th
October 2011 eChallenges e-2011 Copyright 2011 SAP Research
Motivation, Problem Area
“An undefined problem has an infinite number of solutions”
Robert A. Humphrey
Customer Data
Legislation
Government
Auditor
Compliance CheckCompliance Report
Regulation
Regulator
creates creates
Businesses
have to
comply with
store and are
responsible for
use IT to improve
operations
IT Department
have to
comply with
Governance
Compliance
Customer Data
Legislation
Government
Auditor
Compliance CheckCompliance Report
Regulation
Regulator
creates creates
Businesses
have to
comply with
store and are
responsible for
use IT to improve
operations
IT Department
have to
comply with
Governance
Compliance
Session 2b, 26th
October 2011 eChallenges e-2011 Copyright 2011 SAP Research
Research Objectives
• The locality of data is of key importance to adhere to legislation
– Cross-jurisdictional conflictions
– Performance and Availability
– Disaster Recovery and Backup
• Multi-tenancy and data accessibility
– Company Multi-tenancy
– Systems Multi-tenancy
• Data Retention
– Retaining data in the Cloud
– Retaining data from the Cloud
“The greatest challenge to any thinker is stating the problem in a way that will allow a solution.”
Bertrand Russell
Session 2b, 26th
October 2011 eChallenges e-2011 Copyright 2011 SAP Research
CloudCloud
AuditorAuditor
Research Approach, Methodology
“Most human beings have an almost infinite capacity for taking things for granted”
Aldous Huxley
Session 2b, 26th
October 2011 eChallenges e-2011 Copyright 2011 SAP Research
Major Outcomes/Results
“A complex system that works is invariably found to have evolved from a simple system that works”
John Gaule
Session 2b, 26th
October 2011 eChallenges e-2011 Copyright 2011 SAP Research
Conclusion and Outlook
• Ensure the security of consumer’s data
• Maintain compliance with data security / privacy laws
• Assure that service providers, integrators or composers cannot
• access data within a consumer’s service
• transfer data from a consumer’s service
“A conclusion is the place where you got tired of thinking”
Harold Fricklestein
Session 2b, 26th
October 2011 eChallenges e-2011 Copyright 2011 SAP Research
Thank You!
Jonathan Sinclair
Research Associate
SAP Research Belfast
SAP [UK] Ltd
The Concourse, Queen‘s Road
Queen‘s Island, Titanic Quarter
Belfast BT3 9DT
T +44 (0)28 9078 5749
E jonathan.sinclair@sap.com
Blogger:
cloudauditing.blogspot.com
LinkedIn:
jonathangsinclair
Twitter:
jonnygsinclair
Slideshare:
jonathansinclair86

More Related Content

PDF
Emerging IoT in the Energy Sector
PPTX
cloud abstract
PPTX
Connections Cloud Talk
PDF
The iEx.ec Distributed Cloud: Latest Developments and Perspectives
PPTX
DER Integration Testbed at a Glance
PDF
The Convergence of IT, Operational Technology and the Internet of Things (IoT)
PPTX
Integrity for join queries
PDF
Big data appliances for BI on Cloud
Emerging IoT in the Energy Sector
cloud abstract
Connections Cloud Talk
The iEx.ec Distributed Cloud: Latest Developments and Perspectives
DER Integration Testbed at a Glance
The Convergence of IT, Operational Technology and the Internet of Things (IoT)
Integrity for join queries
Big data appliances for BI on Cloud

What's hot (20)

PDF
TheValueChain Beyond Simple 10-05-16 - Internet of Things
PDF
Characterizing Incidents in Cloud-based IoT Data Analytics
PDF
SFScon 21 - Nicola Altamura - Implementation of IOTA solutions on embedded de...
DOCX
Energy efficient fault-tolerant data storage & processing in mobile cloud
PDF
Tim scottkoenverheyenpresentation
PPTX
Benefits of cloud computing
PDF
Energy efficient fault-tolerant data storage and processing in mobile cloud
PPSX
Cloud Computing Introduction
PPTX
The potential of the cloud
PPT
Adoptive Gateways for dIverse MuLtiple Environments
PPTX
How to Architect Smarter Systems for Healthcare
PPTX
SMART Seminar Series: "From cloud-sourced flood mapping to connected communit...
PDF
Data Science for Effective Network Operations
PDF
Engineering and OW2 Big Data Initiative: an open approach to the data-driven ...
PDF
Cloud computing and managed services (Sumit Dutta, CSSWA)
PPT
Asset Intelligence
PPT
Open Source at GLA - a road less travelled
PDF
2014.11 meetup presentation v1
PDF
NordForsk Open Access Reykjavik 14-15/8-2014:NeIC
PPTX
Improving Innovation Through Open Data - Construction Excellence Annual Confe...
TheValueChain Beyond Simple 10-05-16 - Internet of Things
Characterizing Incidents in Cloud-based IoT Data Analytics
SFScon 21 - Nicola Altamura - Implementation of IOTA solutions on embedded de...
Energy efficient fault-tolerant data storage & processing in mobile cloud
Tim scottkoenverheyenpresentation
Benefits of cloud computing
Energy efficient fault-tolerant data storage and processing in mobile cloud
Cloud Computing Introduction
The potential of the cloud
Adoptive Gateways for dIverse MuLtiple Environments
How to Architect Smarter Systems for Healthcare
SMART Seminar Series: "From cloud-sourced flood mapping to connected communit...
Data Science for Effective Network Operations
Engineering and OW2 Big Data Initiative: an open approach to the data-driven ...
Cloud computing and managed services (Sumit Dutta, CSSWA)
Asset Intelligence
Open Source at GLA - a road less travelled
2014.11 meetup presentation v1
NordForsk Open Access Reykjavik 14-15/8-2014:NeIC
Improving Innovation Through Open Data - Construction Excellence Annual Confe...
Ad

Viewers also liked (14)

PDF
Infographic RBD Nordic-Baltic - 2016 Final
PDF
Presentation Kenzen Paleo Bar™ Slide Show 4-16-16
PDF
Natives_guide_2017.compressed
PPTX
Bursting The Filter Bubble
PPTX
What are the Key Customer Experience Mistakes that Brands Make?
PDF
MikeGTaylor
PPTX
Paola medina
DOCX
stroud-david-resume (1) (1) (1)
PPTX
Λεωφορείο-Μέσο συγκοινωνίας
PPTX
Bonitasoft BPMN Presentation
PDF
Informal email 3º
PPTX
Presentation by Chris Uttley, Stroud RSuds Project Officer - Delivery of Natu...
DOCX
Production schedule
Infographic RBD Nordic-Baltic - 2016 Final
Presentation Kenzen Paleo Bar™ Slide Show 4-16-16
Natives_guide_2017.compressed
Bursting The Filter Bubble
What are the Key Customer Experience Mistakes that Brands Make?
MikeGTaylor
Paola medina
stroud-david-resume (1) (1) (1)
Λεωφορείο-Μέσο συγκοινωνίας
Bonitasoft BPMN Presentation
Informal email 3º
Presentation by Chris Uttley, Stroud RSuds Project Officer - Delivery of Natu...
Production schedule
Ad

Similar to eChallenges_e2011_JS (20)

PPTX
Cloud Compliance Auditing - Closer 2011
PPTX
Cloud Audit and Compliance
DOCX
Cloud Computing - Emerging Opportunities in the CA Profession
PDF
Cloud Auditing
PPT
Auditing in the Cloud
PDF
The Art of Cloud Auditing - ISACA ID
PPT
Cloud computing security and privacy christian goire
PDF
Security And Legal In The Cloud Ats V2
PPTX
Non-functional Issues in Cloud Based Systems by Kees Blokland and Martin Pol
PDF
Legal issues in the cloud renzo marchini & gene landy
PPTX
cloud security.pptx
PDF
Cloud Computing and Data Governance
PPTX
Review_2013
PPTX
Legal & Commercial, Issues of a Cloud Service
PPTX
Towards secure and dependable storage
PDF
Auditing & Assessing The Risk Of Cloud Service Providers at Auditworld 2015 ...
PPT
Simultaneously Supporting Privacy and Auditing in Cloud Computing Systems
PDF
It auditing to assure a secure cloud computing
PPSX
Why the Cloud can be Compliant and Secure
PDF
Bird&Bird
Cloud Compliance Auditing - Closer 2011
Cloud Audit and Compliance
Cloud Computing - Emerging Opportunities in the CA Profession
Cloud Auditing
Auditing in the Cloud
The Art of Cloud Auditing - ISACA ID
Cloud computing security and privacy christian goire
Security And Legal In The Cloud Ats V2
Non-functional Issues in Cloud Based Systems by Kees Blokland and Martin Pol
Legal issues in the cloud renzo marchini & gene landy
cloud security.pptx
Cloud Computing and Data Governance
Review_2013
Legal & Commercial, Issues of a Cloud Service
Towards secure and dependable storage
Auditing & Assessing The Risk Of Cloud Service Providers at Auditworld 2015 ...
Simultaneously Supporting Privacy and Auditing in Cloud Computing Systems
It auditing to assure a secure cloud computing
Why the Cloud can be Compliant and Secure
Bird&Bird

eChallenges_e2011_JS

  • 1. Session 2b, 26th October 2011 eChallenges e-2011 Copyright 2011 SAP Research Auditing Issues for Cloud-based Business Services Jonathan Sinclair SAP Research Belfast UK
  • 2. Session 2b, 26th October 2011 eChallenges e-2011 Copyright 2011 SAP Research Agenda • Fundamentals of Cloud, Compliance and Auditing • Cloud Compliance Challenges • Use Case: Future Healthcare and CRM • Compliance Auditing • Conclusions
  • 3. Session 2b, 26th October 2011 eChallenges e-2011 Copyright 2011 SAP Research Fundamentals Compliance Compliance is defined as being in accordance with relevant governmental orindustrial laws, regulationsand standards through governance processes. Business Web A business model and technical framework that represents a marketplace allowing providers and consumers to negotiate the usage of products. Clouds are a large pool of easily usable and accessible virtualized resources that can be dynamically reconfigured to adjust to a variable load. Cloud Computing Auditing The process of collecting and evaluating evidence to determine whether a computer system (information system) safeguards assets, maintains data integrity, achieves organizational goals effectively and consumes resources efficiently.
  • 4. Session 2b, 26th October 2011 eChallenges e-2011 Copyright 2011 SAP Research Motivation, Problem Area “An undefined problem has an infinite number of solutions” Robert A. Humphrey Customer Data Legislation Government Auditor Compliance CheckCompliance Report Regulation Regulator creates creates Businesses have to comply with store and are responsible for use IT to improve operations IT Department have to comply with Governance Compliance Customer Data Legislation Government Auditor Compliance CheckCompliance Report Regulation Regulator creates creates Businesses have to comply with store and are responsible for use IT to improve operations IT Department have to comply with Governance Compliance
  • 5. Session 2b, 26th October 2011 eChallenges e-2011 Copyright 2011 SAP Research Research Objectives • The locality of data is of key importance to adhere to legislation – Cross-jurisdictional conflictions – Performance and Availability – Disaster Recovery and Backup • Multi-tenancy and data accessibility – Company Multi-tenancy – Systems Multi-tenancy • Data Retention – Retaining data in the Cloud – Retaining data from the Cloud “The greatest challenge to any thinker is stating the problem in a way that will allow a solution.” Bertrand Russell
  • 6. Session 2b, 26th October 2011 eChallenges e-2011 Copyright 2011 SAP Research CloudCloud AuditorAuditor Research Approach, Methodology “Most human beings have an almost infinite capacity for taking things for granted” Aldous Huxley
  • 7. Session 2b, 26th October 2011 eChallenges e-2011 Copyright 2011 SAP Research Major Outcomes/Results “A complex system that works is invariably found to have evolved from a simple system that works” John Gaule
  • 8. Session 2b, 26th October 2011 eChallenges e-2011 Copyright 2011 SAP Research Conclusion and Outlook • Ensure the security of consumer’s data • Maintain compliance with data security / privacy laws • Assure that service providers, integrators or composers cannot • access data within a consumer’s service • transfer data from a consumer’s service “A conclusion is the place where you got tired of thinking” Harold Fricklestein
  • 9. Session 2b, 26th October 2011 eChallenges e-2011 Copyright 2011 SAP Research Thank You! Jonathan Sinclair Research Associate SAP Research Belfast SAP [UK] Ltd The Concourse, Queen‘s Road Queen‘s Island, Titanic Quarter Belfast BT3 9DT T +44 (0)28 9078 5749 E jonathan.sinclair@sap.com Blogger: cloudauditing.blogspot.com LinkedIn: jonathangsinclair Twitter: jonnygsinclair Slideshare: jonathansinclair86