<?xml version='1.0' encoding='iso-8859-1' ?><rss version="2.0"><channel><title>Cloud Computing</title><link>http://www.checklist20.com/bestpractices.html</link><description>Cloud Computing</description><item><title>Audit release management and production change management process </title><link>http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=474&amp;tn=Audit release management and production change management process </link><description>If   changes made by CSP is not properly managed tenant's services will be   impacted ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=474&amp;tn=Audit release management and production change management process '>View More</a>]]></description></item><item><title>Review information security policy of the cloud service provider</title><link>http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=472&amp;tn=Review information security policy of the cloud service provider</link><description>Information   stored with the cloud service provider is the key to the kingdom.&amp;nbsp; Sound information security policies   protects tenant's data. ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=472&amp;tn=Review information security policy of the cloud service provider'>View More</a>]]></description></item><item><title>Review incident management and reporting  </title><link>http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=473&amp;tn=Review incident management and reporting  </link><description>To   triage security related events and ensure timely and thorough incident   management a robust incident management process and procedure need to be in   place. ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=473&amp;tn=Review incident management and reporting  '>View More</a>]]></description></item><item><title>Ensure layered defense, multi-level authentication & access controls are implemented to access network</title><link>http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=460&amp;tn=Ensure layered defense, multi-level authentication & access controls are implemented to access network</link><description>Access   by&amp;nbsp; unauthorized internal or external   persons need to be controlled by layered defense with multiple authentication   and access controls. ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=460&amp;tn=Ensure layered defense, multi-level authentication & access controls are implemented to access network'>View More</a>]]></description></item><item><title>Develop and implement facility and physical security policy </title><link>http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=470&amp;tn=Develop and implement facility and physical security policy </link><description>Insufficient   physical controls to facilities has huge exposure to data theft. ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=470&amp;tn=Develop and implement facility and physical security policy '>View More</a>]]></description></item><item><title>Limit use of live production data in the non-production environment </title><link>http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=469&amp;tn=Limit use of live production data in the non-production environment </link><description>Non-production   env. has less security controls compared to the production env.   Replicating&amp;nbsp; the production data in   non-production env. introduces additional risks. ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=469&amp;tn=Limit use of live production data in the non-production environment '>View More</a>]]></description></item><item><title>Validate secure disposal or removal of data </title><link>http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=468&amp;tn=Validate secure disposal or removal of data </link><description>Data   theft during disposal of data ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=468&amp;tn=Validate secure disposal or removal of data '>View More</a>]]></description></item><item><title>Evaluate disaster recovery and  business continuity process </title><link>http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=467&amp;tn=Evaluate disaster recovery and  business continuity process </link><description>Loss of   corporate data and or data processing activities that support mission   critical applications and services. ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=467&amp;tn=Evaluate disaster recovery and  business continuity process '>View More</a>]]></description></item><item><title>Review encryption key management process </title><link>http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=466&amp;tn=Review encryption key management process </link><description>If   encryption keys&amp;nbsp; are not securely   protected against unauthorized access sensitive data might be exposed. In   addition,&amp;nbsp; separation of duties between   the key managers and the hosting organization provides additional control to   ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=466&amp;tn=Review encryption key management process '>View More</a>]]></description></item><item><title>Verify data management and backup process </title><link>http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=465&amp;tn=Verify data management and backup process </link><description>Backing   up data in databases and file systems is key to recover the systems back to   normal state in case of a disaster or user error. ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=465&amp;tn=Verify data management and backup process '>View More</a>]]></description></item><item><title>Ensure the protection of data-at-rest against the deliberate or accidental access of unauthorized persons </title><link>http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=464&amp;tn=Ensure the protection of data-at-rest against the deliberate or accidental access of unauthorized persons </link><description>Data   is&amp;nbsp; securely stored&amp;nbsp; and maintained to prevent unauthorized   access and modification. ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=464&amp;tn=Ensure the protection of data-at-rest against the deliberate or accidental access of unauthorized persons '>View More</a>]]></description></item><item><title>Ensure the protection of in-transit data against the deliberate or accidental access of unauthorized persons </title><link>http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=463&amp;tn=Ensure the protection of in-transit data against the deliberate or accidental access of unauthorized persons </link><description>Data   is&amp;nbsp; securely transmitted and maintained   to prevent unauthorized access and modification. ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=463&amp;tn=Ensure the protection of in-transit data against the deliberate or accidental access of unauthorized persons '>View More</a>]]></description></item><item><title>Ensure SLAs with the cloud service provider covers all the legal, regulatory and business requirements </title><link>http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=462&amp;tn=Ensure SLAs with the cloud service provider covers all the legal, regulatory and business requirements </link><description>Clearly   defined service level agreements with the cloud service provider that&amp;nbsp; help set the expectation with the business   users' requirements. ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=462&amp;tn=Ensure SLAs with the cloud service provider covers all the legal, regulatory and business requirements '>View More</a>]]></description></item><item><title>Classify data stored with the cloud service providers </title><link>http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=461&amp;tn=Classify data stored with the cloud service providers </link><description>Data   classification helps protect the most sensitive data stored in the cloud   infrastructure and providing higher level of security controls ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=171&amp;cn=Cloud Computing&amp;tid=461&amp;tn=Classify data stored with the cloud service providers '>View More</a>]]></description></item></channel></rss>
