Management must ensure cloud use is compliant—All
providers and users of the cloud must comply with regulatory,
legal, contractual and policy obligations; uphold the values
of integrity and client commitment; and ensure that all use
is appropriate and authorised. This is related to the culture
dimension of BMIS. In the case study, the retail banking
operational risk manager works with the compliance manager
to ensure that all policies, regulations and employee codes of
conduct are in place; training is performed; and compliance
is periodically reviewed. The operational risk manager works
with the IT risk manager and vendor manager to ensure that
processes are in place to similarly assess compliance within
the cloud service provider.
The final phase in the cloud computing road map is
sustainability, and there are two related principles:
9. Management must monitor risk in the cloud—All