SaaS, PaaS, IaaS: Audit Considerations by Cloud Model
Understand the audit implications of each cloud service model and shared responsibility concepts for CISA exam preparation.
Cloud computing has transformed how organizations acquire and manage IT services. For CISA candidates, understanding the three primary cloud service models and their audit implications is essential because each model distributes responsibilities differently between the cloud provider and the customer.
The Shared Responsibility Model
The shared responsibility model defines which security and operational controls are managed by the cloud provider and which remain the customer's responsibility. This distribution varies significantly by service model.
Infrastructure as a Service (IaaS)
IaaS provides virtualized computing resources (servers, storage, networking) on demand. The customer manages everything above the infrastructure layer.
Customer Responsibilities
- Operating system installation, patching, and hardening
- Application deployment, configuration, and security
- Data encryption, access control, and backup
- Network security (firewalls, security groups, network segmentation)
- Identity and access management for workloads
Audit Considerations for IaaS
- Verify that the customer maintains adequate controls over their managed layers
- Assess whether security configurations (firewalls, access controls) are appropriate
- Review patch management processes for operating systems and applications
- Evaluate data protection controls, including encryption at rest and in transit
Platform as a Service (PaaS)
PaaS provides a managed platform for developing and deploying applications. The provider manages the operating system, middleware, and runtime, while the customer manages their applications and data.
Customer Responsibilities
- Application code security and configuration
- Data management, classification, and protection
- User access management within applications
- Application-level logging and monitoring
Audit Considerations for PaaS
- Evaluate application security practices, including secure coding and testing
- Verify that data protection controls are in place at the application level
- Assess whether the provider's platform security certifications are current and relevant
- Review how platform updates and changes are communicated and managed
Software as a Service (SaaS)
SaaS provides complete applications delivered over the internet. The provider manages nearly everything, and the customer primarily manages user access and data.
Customer Responsibilities
- User provisioning, access control, and authentication configuration
- Data classification and handling within the application
- Configuration of application settings and security features
- Monitoring user activity and reviewing access rights
Audit Considerations for SaaS
- Review user access management processes, including provisioning and de-provisioning
- Assess the provider's SOC 2 or equivalent audit reports for control effectiveness
- Evaluate data residency, backup, and recovery capabilities
- Verify that the contract includes appropriate security, SLA, and exit provisions
Cross-Cutting Audit Considerations
Regardless of the cloud model, auditors should assess:
- Vendor Risk Management: Is the cloud provider subject to ongoing risk assessment and monitoring?
- Compliance: Does the cloud arrangement satisfy regulatory requirements for data protection, residency, and audit rights?
- Business Continuity: Are backup, recovery, and failover capabilities adequate and tested?
- Exit Strategy: Can the organization retrieve its data and transition to another provider if needed?
- Third-Party Assurance: Does the provider furnish independent audit reports (SOC 1, SOC 2, ISO 27001) that cover relevant controls?
CISA Exam Tips
The exam frequently tests understanding of which controls the customer is responsible for under each service model. Remember that as you move from IaaS to PaaS to SaaS, the provider assumes more responsibility and the customer retains less. However, the customer always retains responsibility for data classification, user access management, and ensuring that the provider's controls meet their requirements. Also focus on the importance of reviewing provider audit reports (SOC 2) as a key audit procedure for cloud services.