Search icon
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
Cloud Auditing Best Practices

You're reading from  Cloud Auditing Best Practices

Product type Book
Published in Jan 2023
Publisher Packt
ISBN-13 9781803243771
Pages 268 pages
Edition 1st Edition
Languages
Authors (2):
Shinesa Cambric Shinesa Cambric
Profile icon Shinesa Cambric
Michael Ratemo Michael Ratemo
Profile icon Michael Ratemo
View More author details

Table of Contents (16) Chapters

Preface 1. Part 1: The Basics of Cloud Architecture and Navigating – Understanding Enterprise Cloud Auditing Essentials
2. Chapter 1: Cloud Architecture and Navigation 3. Chapter 2: Effective Techniques for Preparing to Audit Cloud Environments 4. Part 2: Cloud Security and IT Controls
5. Chapter 3: Identity and Access Management Controls 6. Chapter 4: Network, Infrastructure, and Security Controls 7. Chapter 5: Financial Resource and Change Management Controls 8. Part 3: Executing an Effective Enterprise Cloud Audit Plan
9. Chapter 6: Tips and Techniques for Advanced Auditing 10. Chapter 7: Tools for Monitoring and Assessing 11. Chapter 8: Walk-Through – Assessing IAM Controls 12. Chapter 9: Walk-Through – Assessing Policy Settings and Resource Controls 13. Chapter 10: Walk-Through – Assessing Change Management, Logging, and Monitoring Policies 14. Index 15. Other Books You May Enjoy

Walk-Through – Assessing Change Management, Logging, and Monitoring Policies

In the previous chapter, we put our knowledge of network, infrastructure, and resource controls to the test. Now, we will practice identifying and assessing change management, logging, and monitoring policies.

In this chapter, we’ll cover the following main topics:

  • Preparing to assess change management controls
  • Assessing audit and logging configurations
  • Assessing change management and configuration policies
  • Assessing monitoring and alerting policies

We will pose sample assessment questions and execute a basic test procedure for each of the topic areas. By the end of this chapter, we will have a deeper understanding of assessing change management, logging, and monitoring policies as part of an enterprise cloud audit.

Preparing to assess change management controls

As we covered in Chapter 5, Financial Resource and Change Management Controls, obtaining a thorough understanding of where logging and history can be found for changes performed is critical to determining which areas within a cloud environment should be scoped for audit. Chapter 5, Financial Resource and Change Management Controls, was where we learned about the use of enabling policies, labels, and tags to control the management of resources.

Change management is a systematic approach to managing changes. The primary objective of the change management process is to facilitate changes to the cloud while minimizing risks to cloud environments.

Cloud environments are designed for agility. In addition, cloud environments facilitate the use of a variety of automation, integration, and deployment tools that allow an organization to make rapid changes. Therefore, in a cloud environment, the visibility of changes is the main control for...

Assessing audit and logging configurations

Logs are files that detail all the events that occur within the cloud. Logs can show deviations from expected activity, giving visibility of potential security issues. Different log types include application, server, access, network logs, and so on. Logging is a practice that enables you to collect and correlate log data from cloud applications, services, and infrastructure. It is performed to help identify issues, measure performance, and optimize configurations. Logging is a valuable tool for security analysis, as it can help an organization maintain an audit trail of transactions performed in the cloud.

The three cloud providers; AWS, Azure, and Google Cloud Platform (GCP) provide native tools for logging. AWS provides AWS CloudTrail and Amazon CloudWatch Logs, Azure provides Azure Monitor Logs while GCP offers Cloud Logging. This is not an exhaustive list, but some of the key tools that are used for audit and logging. Let’s...

Assessing change management and configuration policies

As we covered in Chapter 5, Financial Resource and Change Management Controls, in the cloud, automation is embedded into change management processes. Leveraging automation reduces the opportunity for manual IT control failures. Organizations need to ensure that there are safeguards within the automated process that enforce separation of duties, that the automation workflows are regularly reviewed to ensure they adhere to change controls requirements, and that there is clear visibility and approval for those individuals with access to change the automation workflows or perform approvals as part of the workflows.

Each of the cloud providers has its own set of capabilities that can be used to manage changes. We will look at one capability provided by AWS named AWS Systems Manager | Change Manager.

Change Manager is a tool that can be utilized for managing changes to AWS resources.

To launch Change Manager within AWS Systems...

Assessing monitoring and alerting policies

As we covered in Chapter 7, Tools for Monitoring and Assessing, cloud monitoring is a method of reviewing, observing, and managing the health and security of a cloud. Using monitoring tools, organizations can proactively monitor their cloud environments to identify issues before they become security risks. AWS, Azure, and GCP offer native solutions that an IT auditor can leverage to monitor and assess cloud environments. Let us start by looking at AWS.

AWS

The first monitoring tool an IT auditor can leverage in AWS is Amazon CloudWatch.

Amazon CloudWatch

Amazon CloudWatch is an AWS native monitoring and management service that is designed for the purpose of monitoring the services and resources that are used. Amazon CloudWatch can be used to collect and track metrics, monitor log files, and set alarms, among many other functions. To review these findings, we will need to perform the following steps to launch Amazon CloudWatch...

Summary

In this chapter, we performed a walk-through of change management, logging, and monitoring policies for the AWS, Azure, and GCP platforms. We specifically covered how to assess change management controls, audit and logging configurations, and change management and configuration policies. Finally, we reviewed how an IT auditor can leverage monitoring and alerting policies.

We have reached the end of the book. Well done! I want to thank you for sharing this journey with us. The book has provided a roadmap for how to build and execute effective cloud auditing plans for AWS, Azure, and GCP. We hope this will be a valuable resource that you can utilize, and that it enables you to secure and add real value to the organizations that you audit.

lock icon The rest of the chapter is locked
You have been reading a chapter from
Cloud Auditing Best Practices
Published in: Jan 2023 Publisher: Packt ISBN-13: 9781803243771
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime}