Cloud SeCurity AlliAnCe riSk ASSignment
nAme
inStitution
CourSe
ProfeSSor
dAte
, 2
Cloud Security Alliance Risk Assignment
It is essential to understand cloud computing auditing and why it is a continuous process.
One reason is its rapid and dynamic nature, which keeps changing and evolving. The other thing
to comprehend is the requirements for the management plane security and risks, which one must
account for and are tied to technology, people, and processes when migrating to a cloud-centered
business approach or model. The paper responds to questions regarding these issues.
Response To the Questions
1. Cloud computing auditing should be a continuous exercise and not a point in time by nature
based on the recommendation made on page (59).
There are multiple reasons why cloud computing auditing must require less point-in-time
review and a more continuous process. The main reason is cloud environments’ rapidly
changing, dynamic, and evolving nature. With cloud environments, people sometimes scale
resources down and up, decommission and provision services, and update applications in real
time. A point-in-time auditing often captures a section and snapshot, leaving out vital changes
occurring after it is done (audit). The second reason is that cloud clients and providers usually
share crucial responsibilities for compliance and strict security (Suhonen & Martínez, 2023).
Because these two parties may introduce and make changes, such as modifications of the