29.01.2013 Views

ethics - The Institute of Internal Auditors South Africa

ethics - The Institute of Internal Auditors South Africa

ethics - The Institute of Internal Auditors South Africa

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

AUDITING THE THUNDERS IN THE CLOUD<br />

Figure.1 shows a cluster <strong>of</strong> cloud service providers (CSP). Amazon leads the pack. <strong>The</strong> trend<br />

in <strong>Africa</strong> may be slow but cloud is an undeniable reality. Like any other IT enabled investment<br />

the strategic objectives <strong>of</strong> cloud implementation remain business IT strategy alignment,<br />

value creation (value delivery), risk management (value preservation) and resource management<br />

(optimum utilisation <strong>of</strong> resources).<br />

SERVICE MODELS:<br />

Cloud computing service models are<br />

broadly divided into three categories:<br />

S<strong>of</strong>tware-as-a-Service (SaaS), Platform-asa-Service<br />

(PaaS) and Infrastructure-as-a-<br />

Service (IaaS) also known as Utility Computing.<br />

Collectively all the service models<br />

Figure.2<br />

Broad<br />

Network Access<br />

S<strong>of</strong>tware as a<br />

Service (SaaS)<br />

26 | IA ADVISER September 2011<br />

Rapid Elasticity Measured Service<br />

Resource Pooling<br />

Platform as a<br />

Service (PaaS)<br />

can be referred to as IT as a service (ITaaS)<br />

or the SPI Model.<br />

DEPLOYMENT MODELS:<br />

As illustrated in Figure. 2 there are four deployment<br />

models for cloud services namely<br />

private, community, public and hybrid.<br />

On-Demand<br />

Self-Service<br />

Infrastructure as a<br />

Service (IaaS)<br />

Public Private Hybrid Community<br />

Essential<br />

Characteristics<br />

Service<br />

Models<br />

Deployment<br />

Models<br />

PRIVATE CLOUD<br />

A private cloud is a proprietary network or<br />

a data center that supplies hosted services<br />

to a limited number <strong>of</strong> people. <strong>The</strong> cloud<br />

infrastructure is operated solely for a single<br />

organization. It may be managed by the<br />

organization or a third party, and may exist<br />

on-premises or <strong>of</strong>f premises. When a service<br />

provider uses public cloud resources to create<br />

their private cloud, the result is called<br />

a virtual private cloud. <strong>The</strong> private cloud<br />

deployment method has minimum risk as<br />

identity management and corporate, legal<br />

and regulatory audits are easy to perform.<br />

Scalability and agility options may be limited<br />

in a private model.<br />

COMMUNITY CLOUD<br />

Community cloud infrastructure is shared<br />

by several organizations and supports a<br />

specifi c community that has shared concerns<br />

(e.g., mission, security requirements,<br />

policy, or compliance considerations). It<br />

may be managed by the organizations or a<br />

third party and may be hosted on-premises<br />

or <strong>of</strong>f -premises. Community model may be<br />

a cloud provided for insurance companies<br />

or fi nancial institutions. <strong>The</strong> disadvantage<br />

<strong>of</strong> a community model is that data <strong>of</strong> competitors<br />

may be stored together for example<br />

clients for Hollard and Federal Mutual<br />

Insurance companies may be hosted on<br />

the same database; subject to the contractual<br />

and service agreement with the CSP.<br />

PUBLIC CLOUD<br />

<strong>The</strong> cloud infrastructure is made available<br />

to the general public or a large industry<br />

group and is owned by an organization<br />

selling cloud services. Public CSPs <strong>of</strong>f er<br />

relatively undiff erentiated services. <strong>The</strong>y<br />

sell services to anyone on the Internet. Currently,<br />

Amazon Web Services is the largest<br />

public cloud provider.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!