Organisations have to adapt quickly to changes, continuously investigate innovations and be flexible in order to remain competitive. The information technology (IT) landscape has evolved to enable organisations competitive advantage and to meet targets such as reduced costs, scalability, flexibility, capacity utilisation, higher efficiencies and mobility. Many of these benefits are achieved through the utilisation of technologies such as cloud computing and virtualisation. In many instances cloud computing builds on the capabilities of a virtualised computing infrastructure enabling multi-tenancy, scalability and a highly abstracted cloud model. Even though cloud computing and virtualisation provide significant benefits and cost-effective options for IT hosting and expansion, cloud and virtual IT systems are not risk-free. Risks must be understood to ensure adequate security not only for cloud computing, but also for the underlying technologies enabling cloud computing. The focus of this paper is on mitigation for virtualisation and cloud computing security risks as a fundamental step towards ensuring secure cloud computing environments.
Today's businesses operate in an interconnected and global environment allowing them to collaborate with one another and share information resources. At the same time this interconnectivity exposes the organization to many internal (employees) and external threats. Internal threat is among the top information security issues facing organizations as the human factor is regarded the weakest link in the security chain. To address this “human factor” researchers have suggested the fostering of an information security culture to address the human behavior so that information security becomes a second nature to employees. An important step in the fostering of an information security culture is the assessment of the current state of the culture. This paper focuses on the analysis and comparison of current information security culture assessment approaches, to evaluate their suitability specific for use in the culture change process.
The evolution of manufacturing has given rise to computer-aided manufacturing, reconfigurable manufacturing systems and technology-intensive manufacturing. This in turn requires that new options for computing capability are investigated.
Cloud computing presents a new model for IT service delivery and it typically involves over-a-network, on-demand, self-service access, which is dynamically scalable and elastic, utilising pools of often virtualized resources.Through these features, cloud computing has the potential to improve the way businesses and IT operate by offering fast start-up, flexibility, scalability and cost efficiency.Even though cloud computing provides compelling benefits and cost-effective options for IT hosting and expansion, new risks and opportunities for security exploits are introduced.Standards, policies and controls are therefore of the essence to assist management in protecting and safeguarding systems and data.Management should understand and analyse cloud computing risks in order to protect systems and data from security exploits.The focus of this paper is on mitigation for cloud computing security risks as a fundamental step towards ensuring secure cloud computing environments.
1st International Conference on Cloud Computing and Services Science, Noordwijkerhout, The Netherlands, 7-9 May 2011
Organisations are faced with a number of challenges and issues in decentralised, multiple-server, physical, non-virtualized IT environments. Virtualization in recent years has had a significant impact on computing environments and has introduced benefits, including server consolidation, server and hardware utilization and reduced costs. Virtualization's popularity has led to its growth in many IT environments. This paper provides an overview of the IT challenges in non-virtualized environments and addresses the question of whether virtualization provides the solution to these IT challenges.
The increasing dependence upon Information systems in the last few decades by businesses has resulted in concerns rega rding auditing. IS auditing has changed from auditing “around the computer” to auditing through and with the computer. However, technology is changing and so is the profession of IS auditing. As IS auditing is dependent on Information Technology (IT), it is essential that an IS auditor posses ses IT and auditing knowledge to bridge the gap between the IT and auditing professions. The aim of the study is therefore to define the roles and resp onsibilities expected from IS auditors, based on the different types of audit ass ignments and the steps involved in performing an IS audit assignment. It wil l also describes the basic IT and audit knowledge required from IS auditors ba sed on the roles and responsibilities identified, discusses the soft skill s required from IS auditors to successfully perform an IS audit assignment and def ine the main types of IS audit tools and techniques used most often to assis t IS auditors in executing IS audit roles and responsibilities. The study fina lly presented a suggested IS auditor’s profile.