Cloud Audit Controls is a blog about understanding, auditing, and addressing risk in cloud environments.
This blog is maintained by Christopher Davis, a security solutions architect and author from Dallas, Texas. He notes that "systems and architectures are rapidly converging, hiding complexity with additional layers of abstraction. Simplicity is great for operations — as long as risks are understood and addressed."
The CAC Security Model is an interesting read. It describes the concept of cloud audit assurance and the three cycles that frame the discussion:
- What can you do to provide assurance that your cloud infrastructure serves the purpose for which it was designed while protecting the data?
- Where do you start?
- Where does trust begin?