The Federal Financial Institutions Examination Council (FFIEC) released a statement today on cloud computing, attached below. In their document, the interagency body of federal regulators, stated that they “consider cloud computing to be another form of outsourcing with the same basic risk characteristics and risk management requirements as traditional forms of outsourcing. This paper addresses the key risks of outsourced cloud computing identified in existing guidance.” The FFIEC stated that the attached paper “addresses the key risks of outsourced cloud computing identified in existing guidance.” The FFEIC concluded that,
The fundamentals of risk and risk management defined in the IT Handbook apply to cloud computing as they do to other forms of outsourcing. Cloud computing may require more robust controls due to the nature of the service. When evaluating the feasibility of outsourcing to a cloud-computing service provider, it is important to look beyond potential benefits and to perform a thorough due diligence and risk assessment of elements specific to that service. Vendor management, information security, audits, legal and regulatory compliance, and business continuity planning are key elements of sound risk management and risk mitigation controls for cloud computing. As with other service provider offerings, cloud computing may not be appropriate for all financial institutions.
FFIEC – Outsourced Cloud Computing
The course “Contracting for Cloud Computing Services” is designed to help organizations effectively mitigate the risks associated with cloud computing as described in the FFIEC paper. For more details regarding this course, please see https://www.thomastrappler.com.