Some of the unique aspects of cloud computing can pose new challenges to ERM programs. The apparent simplicity of adopting cloud computing belies how complex its management can become when risks materialize. It would be naïve to think that cloud computing will allow an organization to avoid adverse events – criminal activity, human error, and unforeseen accidents and disruptions – that can befall any type of organization. An effective cloud governance program is highly dependent on an
accurate understanding of the risks combined with well-contemplated risk mitigation or acceptance strategies. By leveraging the COSO ERM framework, management will have an effective and consistent approach in identifying the universe of specific risks and risk responses that each cloud computing opportunity and decision entails.