October 2010
Published By
©2010 The Shared Assessments Program. All Rights Reserved.
Table of Contents
About the Shared Assessments Program ............................................................................................4 Acknowledgments ..............................................................................................................................6 Foreword .............................................................................................................................................7 Introduction.........................................................................................................................................8 Cloud Computing: An Overview ......................................................................................................11 A Risk Management Approach: Common and Delta Controls ........................................................15 Cloud Computing Case Study...........................................................................................................40 Glossary ............................................................................................................................................43 Appendix: Additional Cloud Computing Initiatives.........................................................................48
Evaluating Cloud Risk for the Enterprise: A Shared Assessments Guide ©2010 The Shared Assessments Program. All Rights Reserved.
2
©Shared Assessments 2010 Complete and accurate documents created under the Shared Assessments Program may be downloaded from the official Shared Assessments Program website at www.sharedassessments.org. While retaining copyrights, the Shared Assessments Program makes specific documents available to the public for the purpose of conducting self-assessments and third-party security assessments. Licenses for other uses are available from