African Journal of
Business Management

  • Abbreviation: Afr. J. Bus. Manage.
  • Language: English
  • ISSN: 1993-8233
  • DOI: 10.5897/AJBM
  • Start Year: 2007
  • Published Articles: 4194

Cloud computing adoption: Control objectives for information and related technology (COBIT) - mapped risks and risk mitigating controls

Zacharias Enslin
Department of Accounting, Stellenbosch University, Private Bag X1, Matieland, 7602, South Africa.
Email: [email protected]

  •  Accepted: 03 September 2012
  •  Published: 19 September 2012

Abstract

Cloud computing has emerged as one of the most hyped information technology topics of the decade. Little guidance is given to prospective consumers of the cloud computing services who may not possess technical knowledge, or be interested in the in-depth technical aspects aimed at information technology specialists. The aim of this study is to inform enterprise managers, who possess business knowledge and who may also be knowledgeable on the main aspects of COBIT, about the significant incremental risks this new technological advancement may expose the enterprise to if the proposals of possible controls are implemented by the prospective consumer enterprises to mitigate the incremental risks of cloud computing. An IT governance control framework was used to systematically identify and categorise the significant incremental risks and to assist in identifying the possible risk mitigating controls. It was discovered that the major risks of cloud computing adoption would be outsourcing of IT function (possibly across judicial borders) and the use of internet or wide area access technologies.

 

Key words: Cloud computing, information technology (IT), control objectives for information and related technology (COBIT), IT governance, IT related risk.