Session Summary

Two camps debate over the safety of Cloud Computing, but chances are neither camp was sufficiently consulted before their companies invested substantially in either virtualization infrastructure or moved any number of key business functions into the Cloud. The reality is both auditors and the business have to collaborate in refining existing risk scenarios, address new areas of configuration management, and modify change policies to prevent common pitfalls known to the adoption of any new technology, (i.e., loss of availability, integrity, and reputation). While Cloud and Virtualization pose unprecedented essential business value, (such as avoiding downtime, improving availability, reducing the cost of operations and speeding product to markets) companies that rush to leverage cost savings, are also likely to experience our next biggest losses of all time.

Your company, however, doesn't have to own that headline.

Controlling Risk in Virtualized Environments session discusses practical education and Information Technology approaches providing strategies for effective risk management in Virtualization and Cloud adoption. The topic will cover key cloud concepts & terminology, cloud, and virtualization project components, and their implications for Information Technology Service Management (ITSM) as well as security and legal aspects in governance.

Leveraging guidelines proposed in the CompTIA Cloud and Virtualization Essentials curriculum, this hour will also outline steps organization should take to increase their success rate of implementing cloud computing, improve in-house cloud competencies, and decrease dependence on external consultants and services.

Discussion points include:

  • Service Management - (ITIL):
  • Cloud computing as a set of technologies and an approach to IT service delivery.
  • Governance – (COBIT):
  • Detailing ways that risks should be mitigated such that investments generate value.
  • Information Security- (ISO/IEC 27001):
  • "Risk Management or Governance" through specific "Policy" where information security ensures that information in the cloud is safe and secure.

Speaker Biography

robin basham 2015About Robin Basham, M.ED, M.IT, CISSP, CISA, CGEIT, CRISC, ACC, CRP and VEP, Managing Partner, EnterpriseGRC Solutions Inc., creator of Facilitated Compliance Management Software, and founder of Phoenix Business and Systems Process, Inc. Recent ITPreneurs partner, Robin now leads Cloud and Virtualization training in the San Francisco and Bay Area. As EnterpriseGRC Solutions lead architect, Robin brings team experience leveraging platforms such as Oracle, Archer, SAP, Web Applications like Joomla, Visual Studio, Access, and SharePoint. As an Archer Certified Consultant and SharePoint architect, she's known for successful GRC implementations, supplying overall design, development, and training to companies ranging from start-up to fortune five hundred. Over the last decade, Robin has architect more than 70 GRC programs, delivering end to end solutions with full knowledge transfer to program owners and users. Corporate leadership includes acting as a technical liaison for ISACA in the development of the OCEG Redbook V1, TC Co-Chair for OMG's Open Regulatory Compliance Architecture (ORCA) project, working with co-chairs EMC's Chief Governance Officer, Dr. Marlin Pohlman and world expert, Dr. Said Tabet. Robin's companies remain active in emerging standards with participation on recent releases from ISACA® for both Oracle R12 and SAP ECC 6.0 controls. Ms. Basham is also a director of the Association of Certified Green Technology Auditors, ACGTA, a frequent committee contributor to the ISACA Silicon Valley Chapter and liaison to the ITSMF SV chapter, as well as a participant in Cloud Security Alliance. EntepriseGRC Solutions is recently added to the Cloud Credential Council and is an active sponsor to Information Systems Audit and Control Association, ISACA, listed as a corporate sponsor and many time CobiT trainer for the ITGI.

\
Main Menu