CONTROLS FOR CLOUD COMPUTING ENVIRONMENT
An example computer system for implementing controls for a cloud computing environment can include: one or more processors; and non-transitory computer-readable storage media encoding instructions which, when executed by the one or more processors, causes the computer system to create: a repository engine programmed to consolidate the controls for the cloud computing environment; a workload engine programmed to determine an applicability of the controls to data stored in the cloud computing environment; an adherence validation engine programmed to validate compliance of the controls of the cloud computing environment with the control requirements; a security risk engine programmed to assess security risks associated with the cloud computing environment; and an adherence monitoring engine programmed to continuously monitor compliance of the cloud computing environment with the control requirements and measure changes to the security risks.
1 . A computer system for implementing controls for a cloud computing environment, comprising:
one or more processors; and
non-transitory computer-readable storage media encoding instructions which, when executed by the one or more processors, causes the computer system to create:
a repository engine programmed to consolidate the controls for the cloud computing environment;
a workload engine programmed to determine an applicability of the controls to workload processing and data stored in the cloud computing environment;
an adherence validation engine programmed to validate compliance with the controls of the cloud computing environment;
a security risk engine programmed to assess security risks associated with the workload processing and the data stored in the cloud computing environment; and
an adherence monitoring engine programmed to monitor compliance of the cloud computing environment with the controls and measure changes to the security risks.
2 . The computer system of claim 1 , wherein the repository engine is a centralized repository of the controls.
3 . The computer system of claim 1 , wherein the repository engine is further programmed to keep the controls current.
4 . The computer system of claim 1 , wherein the workload engine is further programmed to select the controls based upon a type of data being stored and other relevant attributes in the cloud computing environment.
5 . The computer system of claim 1 , wherein the workload engine is further programmed to minimize false alerts associated with the controls.
6 . The computer system of claim 1 , wherein the adherence validation engine is further programmed to correlate the data from the cloud computing environment with a local datastore.
7 . The computer system of claim 1 , wherein the adherence validation engine is further programmed to audit the data in the cloud computing environment in near real-time.
8 . The computer system of claim 1 , wherein the security risk engine is further programmed to automatically calculate an aggregated risk associated with the data in the cloud computing environment.
9 . The computer system of claim 1 , wherein the security risk engine is further programmed to compare the security risks to a threshold to determine appropriate alerting.
10 . The computer system of claim 1 , wherein the adherence monitoring engine is further programmed to manage drift associated with the cloud computing environment.
11 . A method for implementing controls for a cloud computing environment, the method comprising:
consolidating the controls for the cloud computing environment;
determining an applicability of the controls to workload processing and data stored in the cloud computing environment;
validating compliance with the controls of the cloud computing environment;
assessing security risks associated with the workload processing and the data stored in the cloud computing environment; and
monitoring compliance of the cloud computing environment with the controls and measure changes to the security risks.
12 . The method of claim 11 , further comprising providing a centralized repository of the controls.
13 . The method of claim 11 , further comprising keeping the controls current.
14 . The method of claim 11 , further comprising selecting the controls based upon a type of data being stored and other relevant attributes in the cloud computing environment.
15 . The method of claim 11 , further comprising minimizing false alerts associated with the controls.
16 . The method of claim 11 , further comprising correlating the data from the cloud computing environment with a local datastore.
17 . The method of claim 11 , further comprising auditing the data in the cloud computing environment in near real-time.
18 . The method of claim 11 , further comprising automatically calculating an aggregated risk associated with the data in the cloud computing environment.
19 . The method of claim 11 , further comprising comparing the security risks to a threshold to determine appropriate alerting.
20 . The method of claim 11 , further comprising managing drift associated with the cloud computing environment.