Search engine for discovering works of Art, research articles, and books related to Art and Culture
ShareThis
Javascript must be enabled to continue!

Comparative Analysis of Cloud Audit Programs: AWS, Azure, GCP, and COBIT 2019 Integration

View through CrossRef
Cloud computing has rapidly established itself as the prevailing model for enterprise IT, with major providers such as Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP) leading global adoption. The cloud promises scalability, flexibility, and cost efficiency, but it also creates complex governance, risk, and compliance challenges due to shared infrastructure, multi-tenancy, and interdependent service layers. To guide assurance efforts, ISACA has issued dedicated audit frameworks: the AWS Audit Program (2019), the Azure Audit Program (2020), the GCP Audit Program (2023), and a broader Cloud Computing Audit Program (2016). These programs structure risk assessment and testing across domains such as governance, identity and access management, incident response, configuration management, logging, and business continuity. To integrate these audit practices with enterprise-level governance, the study employs the COBIT 2019 framework, ISACA’s globally recognized model for governing and managing information and technology. COBIT 2019 provides structured objectives and processes across governance, planning, implementation, service delivery, and monitoring that link IT controls directly to business goals, risk optimization, and value delivery. This study undertakes a comparative review of the cloud audit programs, aligning their focus areas with COBIT 2019’s governance and management objectives. The findings highlight distinct emphases: AWS concentrates on configuration and misconfiguration risks, Azure underscores continuity, shared responsibility, and service reliability, GCP emphasizes hierarchical structure, identity, and permission inheritance, and the general cloud computing program provides a broad governance foundation applicable across providers. Comparative analysis shows Azure exhibits the closest alignment with COBIT 2019, while AWS and GCP reveal gaps in governance integration. To address these gaps, the study proposes harmonization strategies involving cyber-risk quantification, structured risk registers, and continuous auditing. By linking technical audit domains to COBIT 2019’s governance objectives, the study reframes cloud audits from static, checklist-based exercises into dynamic governance mechanisms that foster compliance, risk optimization, and digital trust.
Title: Comparative Analysis of Cloud Audit Programs: AWS, Azure, GCP, and COBIT 2019 Integration
Description:
Cloud computing has rapidly established itself as the prevailing model for enterprise IT, with major providers such as Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP) leading global adoption.
The cloud promises scalability, flexibility, and cost efficiency, but it also creates complex governance, risk, and compliance challenges due to shared infrastructure, multi-tenancy, and interdependent service layers.
To guide assurance efforts, ISACA has issued dedicated audit frameworks: the AWS Audit Program (2019), the Azure Audit Program (2020), the GCP Audit Program (2023), and a broader Cloud Computing Audit Program (2016).
These programs structure risk assessment and testing across domains such as governance, identity and access management, incident response, configuration management, logging, and business continuity.
To integrate these audit practices with enterprise-level governance, the study employs the COBIT 2019 framework, ISACA’s globally recognized model for governing and managing information and technology.
COBIT 2019 provides structured objectives and processes across governance, planning, implementation, service delivery, and monitoring that link IT controls directly to business goals, risk optimization, and value delivery.
This study undertakes a comparative review of the cloud audit programs, aligning their focus areas with COBIT 2019’s governance and management objectives.
The findings highlight distinct emphases: AWS concentrates on configuration and misconfiguration risks, Azure underscores continuity, shared responsibility, and service reliability, GCP emphasizes hierarchical structure, identity, and permission inheritance, and the general cloud computing program provides a broad governance foundation applicable across providers.
Comparative analysis shows Azure exhibits the closest alignment with COBIT 2019, while AWS and GCP reveal gaps in governance integration.
To address these gaps, the study proposes harmonization strategies involving cyber-risk quantification, structured risk registers, and continuous auditing.
By linking technical audit domains to COBIT 2019’s governance objectives, the study reframes cloud audits from static, checklist-based exercises into dynamic governance mechanisms that foster compliance, risk optimization, and digital trust.

Related Results

Impact of water demand for irrigation on the water availability of the Urubu River in Brazil 
Impact of water demand for irrigation on the water availability of the Urubu River in Brazil 
<p>There are 37 hydraulic water catchment pumps installed in the Urubu River hydrographic basin, located in an important agricultural area in the northern region of B...
Paper K-9 Pelaporan Hasil Audit dan Tindak Lanjut Audit Internal
Paper K-9 Pelaporan Hasil Audit dan Tindak Lanjut Audit Internal
Pelaporan hasil audit merupakan komponen utama dalam komunikasi dari audit internal tentang hasil audit. Untuk mengkomunikasikan hasil audit diperlukan susunan laporan, dimana hasi...
Study on Good Clinical Practices among Researchers in a Tertiary Healthcare Institute in India
Study on Good Clinical Practices among Researchers in a Tertiary Healthcare Institute in India
Abstract BACKGROUND Good Clinical Practice (GCP) is put in place to protect human participants in clinical trials as well as to...
Decoding the Cloud Giants: A Comparison of AWS, Azure and GCP
Decoding the Cloud Giants: A Comparison of AWS, Azure and GCP
The adoption of cloud services by companies and organizations is increasingly becoming essential for enhancing competitive performance in today's business environment. Cloud servic...
CLOUD COMPUTING - NAVIGATING THE DIGITAL SKY
CLOUD COMPUTING - NAVIGATING THE DIGITAL SKY
“Cloud Computing – Navigating the Digital Sky” is an extensive guide designed to provide a thorough understanding of cloud computing, an essential technology in today’s digital age...
Primerjalna književnost na prelomu tisočletja
Primerjalna književnost na prelomu tisočletja
In a comprehensive and at times critical manner, this volume seeks to shed light on the development of events in Western (i.e., European and North American) comparative literature ...
Integrating Azure Services for Real Time Data Analytics and Big Data Processing
Integrating Azure Services for Real Time Data Analytics and Big Data Processing
Integrating Azure services for real-time data analytics and big data processing is a transformative approach that leverages the power of cloud computing to handle vast amounts of d...
DETERMINAN FEE AUDIT
DETERMINAN FEE AUDIT
ABSTRACT This study aims to examine the factors that affect audit fees. Factors examined include  factors derived from the entity (client) and the factors derived from the auditor....

Back to Top