« The IT Pendulum Swings | Main | The diamond in the iPhone 3G rough »
TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d8345190da69e200e553935c3b8833
Listed below are links to weblogs that reference A threat to clouds?:
» Auditing IT systems from Keystones and Rivets
To be able to accurately assess risk of IT system failure, three things need to be clearly understood and easily communicable [Read More]
A threat to clouds?
The sad thing about SOX (and I railed so much about it in 2006 and 2007) was it often was more as a reason to say no to many innovations - largely because auditors did not understand the proposals or it was outside their comfort zone. In the meantime, investments in SOX related controls and technology were pushed through with little consideration of ROI. So, compliance spend crowded out money that could have gone towards innovation. So, a double whammy...
Over the weekend I had a conversation with Dennis Howlett and Francine McKenna about whether auditors are keeping up newer issues coming up with SaaS and cloud computing - are the SAS 70 audits keeping up with unique multi-tenancy, virtualization, shared across customer asset issues? The initial answer that Francine summarizes here is - not really.
I sure hope we don't end up with a scenario where the auditors end up being the obstacle to adoption of SaaS and cloud computing because they don't understand them well enough. And worse, they come up the next-gen SOX which threatens to crowd out these newer waves of innovations...
July 10, 2008 in Industry Commentary | Permalink