<?xml version="1.0" encoding="UTF-8"?>
<record
    xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    xsi:schemaLocation="http://www.loc.gov/MARC21/slim http://www.loc.gov/standards/marcxml/schema/MARC21slim.xsd"
    xmlns="http://www.loc.gov/MARC21/slim">

  <leader>08214cam a2200757Ia 4500</leader>
  <controlfield tag="001">ocn747412460</controlfield>
  <controlfield tag="003">OCoLC</controlfield>
  <controlfield tag="005">20171116112940.0</controlfield>
  <controlfield tag="006">m     o  d        </controlfield>
  <controlfield tag="007">cr cn|||||||||</controlfield>
  <controlfield tag="008">110418s2011    njua    ob    001 0 eng d</controlfield>
  <datafield tag="020" ind1=" " ind2=" ">
    <subfield code="a">9781118269091</subfield>
    <subfield code="q">(electronic bk.)</subfield>
  </datafield>
  <datafield tag="020" ind1=" " ind2=" ">
    <subfield code="a">1118269098</subfield>
    <subfield code="q">(electronic bk.)</subfield>
  </datafield>
  <datafield tag="020" ind1=" " ind2=" ">
    <subfield code="a">9781118116036</subfield>
    <subfield code="q">(electronic bk.)</subfield>
  </datafield>
  <datafield tag="020" ind1=" " ind2=" ">
    <subfield code="a">1118116038</subfield>
    <subfield code="q">(electronic bk.)</subfield>
  </datafield>
  <datafield tag="020" ind1=" " ind2=" ">
    <subfield code="a">9781118116043</subfield>
    <subfield code="q">(electronic bk.)</subfield>
  </datafield>
  <datafield tag="020" ind1=" " ind2=" ">
    <subfield code="a">1118116046</subfield>
    <subfield code="q">(electronic bk.)</subfield>
  </datafield>
  <datafield tag="020" ind1=" " ind2=" ">
    <subfield code="a">9781118116029</subfield>
    <subfield code="q">(electronic bk.)</subfield>
  </datafield>
  <datafield tag="020" ind1=" " ind2=" ">
    <subfield code="a">111811602X</subfield>
    <subfield code="q">(electronic bk.)</subfield>
  </datafield>
  <datafield tag="020" ind1=" " ind2=" ">
    <subfield code="z">9780470874745</subfield>
    <subfield code="q">(print)</subfield>
  </datafield>
  <datafield tag="020" ind1=" " ind2=" ">
    <subfield code="z">0470874740</subfield>
    <subfield code="q">(print)</subfield>
  </datafield>
  <datafield tag="029" ind1="1" ind2=" ">
    <subfield code="a">AU@</subfield>
    <subfield code="b">000053396245</subfield>
  </datafield>
  <datafield tag="029" ind1="1" ind2=" ">
    <subfield code="a">CHNEW</subfield>
    <subfield code="b">000607104</subfield>
  </datafield>
  <datafield tag="029" ind1="1" ind2=" ">
    <subfield code="a">DEBBG</subfield>
    <subfield code="b">BV041167590</subfield>
  </datafield>
  <datafield tag="029" ind1="1" ind2=" ">
    <subfield code="a">DEBBG</subfield>
    <subfield code="b">BV041558921</subfield>
  </datafield>
  <datafield tag="029" ind1="1" ind2=" ">
    <subfield code="a">DEBBG</subfield>
    <subfield code="b">BV042032057</subfield>
  </datafield>
  <datafield tag="029" ind1="1" ind2=" ">
    <subfield code="a">DEBSZ</subfield>
    <subfield code="b">372700403</subfield>
  </datafield>
  <datafield tag="029" ind1="1" ind2=" ">
    <subfield code="a">DEBSZ</subfield>
    <subfield code="b">414175247</subfield>
  </datafield>
  <datafield tag="029" ind1="1" ind2=" ">
    <subfield code="a">DKDLA</subfield>
    <subfield code="b">820120-katalog:000588414</subfield>
  </datafield>
  <datafield tag="029" ind1="1" ind2=" ">
    <subfield code="a">NZ1</subfield>
    <subfield code="b">14693208</subfield>
  </datafield>
  <datafield tag="035" ind1=" " ind2=" ">
    <subfield code="a">(OCoLC)747412460</subfield>
    <subfield code="z">(OCoLC)821030850</subfield>
    <subfield code="z">(OCoLC)876268681</subfield>
  </datafield>
  <datafield tag="037" ind1=" " ind2=" ">
    <subfield code="a">CL0500000409</subfield>
    <subfield code="b">Safari Books Online</subfield>
  </datafield>
  <datafield tag="037" ind1=" " ind2=" ">
    <subfield code="a">F889EE2A-CF12-4647-85E0-03258F227FC1</subfield>
    <subfield code="b">OverDrive, Inc.</subfield>
    <subfield code="n">http://www.overdrive.com</subfield>
  </datafield>
  <datafield tag="040" ind1=" " ind2=" ">
    <subfield code="a">E7B</subfield>
    <subfield code="b">eng</subfield>
    <subfield code="e">pn</subfield>
    <subfield code="c">E7B</subfield>
    <subfield code="d">OCLCQ</subfield>
    <subfield code="d">YDXCP</subfield>
    <subfield code="d">WAU</subfield>
    <subfield code="d">CDX</subfield>
    <subfield code="d">N$T</subfield>
    <subfield code="d">B24X7</subfield>
    <subfield code="d">DG1</subfield>
    <subfield code="d">TEFOD</subfield>
    <subfield code="d">REDDC</subfield>
    <subfield code="d">OCLCQ</subfield>
    <subfield code="d">DEBSZ</subfield>
    <subfield code="d">OCLCQ</subfield>
    <subfield code="d">DKDLA</subfield>
    <subfield code="d">OCLCO</subfield>
    <subfield code="d">UMI</subfield>
    <subfield code="d">DEBBG</subfield>
    <subfield code="d">OCLCO</subfield>
    <subfield code="d">NLGGC</subfield>
    <subfield code="d">TEFOD</subfield>
    <subfield code="d">EBLCP</subfield>
    <subfield code="d">OCLCQ</subfield>
    <subfield code="d">OCLCO</subfield>
    <subfield code="d">OCLCQ</subfield>
    <subfield code="d">DG1</subfield>
    <subfield code="d">ELW</subfield>
  </datafield>
  <datafield tag="049" ind1=" " ind2=" ">
    <subfield code="a">MAIN</subfield>
  </datafield>
  <datafield tag="050" ind1=" " ind2="4">
    <subfield code="a">HF5548.37</subfield>
    <subfield code="b">.A93 2011eb</subfield>
  </datafield>
  <datafield tag="072" ind1=" " ind2="7">
    <subfield code="a">COM</subfield>
    <subfield code="x">060040</subfield>
    <subfield code="2">bisacsh</subfield>
  </datafield>
  <datafield tag="072" ind1=" " ind2="7">
    <subfield code="a">COM</subfield>
    <subfield code="x">043050</subfield>
    <subfield code="2">bisacsh</subfield>
  </datafield>
  <datafield tag="072" ind1=" " ind2="7">
    <subfield code="a">COM</subfield>
    <subfield code="x">053000</subfield>
    <subfield code="2">bisacsh</subfield>
  </datafield>
  <datafield tag="082" ind1="0" ind2="4">
    <subfield code="a">005.8</subfield>
    <subfield code="2">22</subfield>
  </datafield>
  <datafield tag="245" ind1="0" ind2="0">
    <subfield code="a">Auditing cloud computing : a security and privacy guide /</subfield>
    <subfield code="c">[edited by] Ben Halpert.</subfield>
    <subfield code="h">[electronic resource]</subfield>
  </datafield>
  <datafield tag="260" ind1=" " ind2=" ">
    <subfield code="a">Hoboken, N.J. :</subfield>
    <subfield code="b">John Wiley &amp; Sons,</subfield>
    <subfield code="c">&#xA9;2011.</subfield>
  </datafield>
  <datafield tag="300" ind1=" " ind2=" ">
    <subfield code="a">1 online resource (xvi, 206 pages) :</subfield>
    <subfield code="b">illustrations.</subfield>
  </datafield>
  <datafield tag="336" ind1=" " ind2=" ">
    <subfield code="a">text</subfield>
    <subfield code="b">txt</subfield>
    <subfield code="2">rdacontent</subfield>
  </datafield>
  <datafield tag="337" ind1=" " ind2=" ">
    <subfield code="a">computer</subfield>
    <subfield code="b">c</subfield>
    <subfield code="2">rdamedia</subfield>
  </datafield>
  <datafield tag="338" ind1=" " ind2=" ">
    <subfield code="a">online resource</subfield>
    <subfield code="b">cr</subfield>
    <subfield code="2">rdacarrier</subfield>
  </datafield>
  <datafield tag="490" ind1="1" ind2=" ">
    <subfield code="a">[Wiley corporate F &amp; A] ;</subfield>
    <subfield code="v">21</subfield>
  </datafield>
  <datafield tag="504" ind1=" " ind2=" ">
    <subfield code="a">Includes bibliographical references and index.</subfield>
  </datafield>
  <datafield tag="505" ind1="0" ind2=" ">
    <subfield code="a">Preface xiii Chapter 1: Introduction to Cloud Computing 1 History 1 Defining Cloud Computing 2 Elasticity 2 Multitenancy 3 Economics 3 Abstraction 3 Cloud Computing Services Layers 4 Infrastructure as a Service 5 Platform as a Service 5 Software as a Service 6 Roles in Cloud Computing 6 Consumer 6 Provider 6 Integrator 7 Cloud Computing Deployment Models 8 Private 8 Community 8 Public 9 Hybrid 9 Challenges 9 Availability 10 Data Residency 10 Multitenancy 11 Performance 11 Data Evacuation 12 Supervisory Access 12 In Summary 13 Chapter 2: Cloud-Based IT Audit Process 15 The Audit Process 16 Control Frameworks for the Cloud 18 ENISA Cloud Risk Assessment 20 FedRAMP 20 Entities Using COBIT 21 CSA Guidance 21 CloudAudit/A6 -- The Automated Audit, Assertion, Assessment, and Assurance API 22 Recommended Controls 22 Risk Management and Risk Assessment 26 Risk Management 27 Risk Assessment 27 Legal 28 In Summary 29 Chapter 3: Cloud-Based IT Governance 33 Governance in the Cloud 36 Understanding the Cloud 36 Security Issues in the Cloud 37 Abuse and Nefarious Use of Cloud Computing 38 Insecure Application Programming Interfaces 39 Malicious Insiders 39 Shared Technology Vulnerabilities 39 Data Loss/Leakage 40 Account, Service, and Traffic Hijacking 40 Unknown Risk Profile 40 Other Security Issues in the Cloud 41 Governance 41 IT Governance in the Cloud 44 Managing Service Agreements 44 Implementing and Maintaining Governance for Cloud Computing 46 Implementing Governance as a New Concept 46 Preliminary Tasks 46 Adopt a Governance Implementation Methodology 48 Extending IT Governance to the Cloud 49 In Summary 52 Chapter 4: System and Infrastructure Lifecycle Management for the Cloud 57 Every Decision Involves Making a Tradeoff 57 Example: Business Continuity/Disaster Recovery 59 What about Policy and Process Collisions? 60 The System and Management Lifecycle Onion 61 Mapping Control Methodologies onto the Cloud62 Information Technology Infrastructure Library 63 Control Objectives for Information and Related Technology 64 National Institute of Standards and Technology 65 Cloud Security Alliance 66 Verifying Your Lifecycle Management 67 Always Start with Compliance Governance 67 Verification Method 68 Illustrative Example 70 Risk Tolerance 72 Special Considerations for Cross-Cloud Deployments 73 The Cloud Provider's Perspective 74 Questions That Matter 75 In Summary 76 Chapter 5: Cloud-Based IT Service Delivery and Support 79 Beyond Mere Migration 80 Architected to Share, Securely 80 Single-Tenant Offsite Operations (Managed Service Providers) 81 Isolated-Tenant Application Services (Application Service Providers) 81 Multitenant (Cloud) Applications and Platforms 82 Granular Privilege Assignment 82 Inherent Transaction Visibility 84 Centralized Community Creation 86 Coherent Customization 88 The Question of Location 90 Designed and Delivered for Trust 91 Fewer Points of Failure91 Visibility and Transparency 93 In Summary 93 Chapter 6: Protection and Privacy of Information Assets in the Cloud 97 The Three Usage Scenarios 99 What Is a Cloud? Establishing the Context -- Defining Cloud Solutions and their Characteristics 100 What Makes a Cloud Solution? 101 Understanding the Characteristics 104 Service Based 104 On-Demand Self-Service 104 Broad Network Access 104 Scalable and Elastic 105 Unpredictable Demand 105 Demand Servicing 105 Resource Pooling 105 Managed Shared Service 105 Auditability 105 Service Termination and Rollback 106 Charge by Quality of Service and Use 106 Capability to Monitor and Quantify Use 106 Monitor and Enforce Service Policies 107 Compensation for Location Independence 107 Multitenancy 107 Authentication and Authorization 108 Confidentiality 108 Integrity 108 Authenticity 108 Availability 108 Accounting and Control 109 Collaboration Oriented Architecture 109 Federated Access and ID Management 10.</subfield>
  </datafield>
  <datafield tag="520" ind1=" " ind2=" ">
    <subfield code="a">"The auditor's guide to ensuring correct security and privacy practices in a cloud computing environment. Many organizations are reporting or projecting a significant cost savings through the use of cloud computing--utilizing shared computing resources to provide ubiquitous access for organizations and end users. Just as many organizations, however, are expressing concern with security and privacy issues for their organization's data in the "cloud." Auditing Cloud Computing provides necessary guidance to build a proper audit to ensure operational integrity and customer data protection, among other aspects, are addressed for cloud based resources. Provides necessary guidance to ensure auditors address security and privacy aspects that through a proper audit can provide a specified level of assurance for an organization's resources. Reveals effective methods for evaluating the security and privacy practices of cloud services. A cloud computing reference for auditors and IT security professionals, as well as those preparing for certification credentials, such as Certified Information Systems Auditor (CISA). Timely and practical, Auditing Cloud Computing expertly provides information to assist in preparing for an audit addressing cloud computing security and privacy for both businesses and cloud based service providers"--</subfield>
    <subfield code="c">Provided by publisher.</subfield>
  </datafield>
  <datafield tag="588" ind1="0" ind2=" ">
    <subfield code="a">Print version record.</subfield>
  </datafield>
  <datafield tag="650" ind1=" " ind2="0">
    <subfield code="a">Business enterprises</subfield>
    <subfield code="x">Computer networks</subfield>
    <subfield code="x">Security measures.</subfield>
  </datafield>
  <datafield tag="650" ind1=" " ind2="0">
    <subfield code="a">Cloud computing</subfield>
    <subfield code="x">Security measures.</subfield>
  </datafield>
  <datafield tag="650" ind1=" " ind2="0">
    <subfield code="a">Information technology</subfield>
    <subfield code="x">Security measures.</subfield>
  </datafield>
  <datafield tag="650" ind1=" " ind2="0">
    <subfield code="a">Data protection.</subfield>
  </datafield>
  <datafield tag="650" ind1=" " ind2="7">
    <subfield code="a">COMPUTERS</subfield>
    <subfield code="x">Internet</subfield>
    <subfield code="x">Security.</subfield>
    <subfield code="2">bisacsh</subfield>
  </datafield>
  <datafield tag="650" ind1=" " ind2="7">
    <subfield code="a">COMPUTERS</subfield>
    <subfield code="x">Networking</subfield>
    <subfield code="x">Security.</subfield>
    <subfield code="2">bisacsh</subfield>
  </datafield>
  <datafield tag="650" ind1=" " ind2="7">
    <subfield code="a">COMPUTERS</subfield>
    <subfield code="x">Security</subfield>
    <subfield code="x">General.</subfield>
    <subfield code="2">bisacsh</subfield>
  </datafield>
  <datafield tag="655" ind1=" " ind2="4">
    <subfield code="a">Electronic books.</subfield>
  </datafield>
  <datafield tag="655" ind1=" " ind2="7">
    <subfield code="a">Electronic books.</subfield>
    <subfield code="2">local</subfield>
  </datafield>
  <datafield tag="700" ind1="1" ind2=" ">
    <subfield code="a">Halpert, Ben,</subfield>
    <subfield code="d">1986-</subfield>
  </datafield>
  <datafield tag="776" ind1="0" ind2="8">
    <subfield code="i">Print version:</subfield>
    <subfield code="t">Auditing cloud computing.</subfield>
    <subfield code="d">Hoboken, N.J. : Wiley, &#xA9;2011</subfield>
    <subfield code="z">9780470874745</subfield>
    <subfield code="w">(DLC)  2011016626</subfield>
    <subfield code="w">(OCoLC)698587265</subfield>
  </datafield>
  <datafield tag="830" ind1=" " ind2="0">
    <subfield code="a">Wiley corporate F &amp; A ;</subfield>
    <subfield code="v">21.</subfield>
  </datafield>
  <datafield tag="856" ind1="4" ind2="0">
    <subfield code="u">http://onlinelibrary.wiley.com/book/10.1002/9781118269091</subfield>
    <subfield code="z">Wiley Online Library</subfield>
  </datafield>
  <datafield tag="942" ind1=" " ind2=" ">
    <subfield code="2">ddc</subfield>
    <subfield code="c">BK</subfield>
  </datafield>
  <datafield tag="999" ind1=" " ind2=" ">
    <subfield code="c">205241</subfield>
    <subfield code="d">205241</subfield>
  </datafield>
</record>
