Cloud Computing Audit for DISA
Moving to the cloud splits the controls. The audit starts by mapping who now runs which one.
When a client moves its ledger, payroll or core banking workloads to a cloud provider, the controls do not disappear. They split. Some stay with the client, some pass to the provider, and a few are shared. An IS auditor's first job in a cloud engagement is to map that split for the specific service model in use, then decide how to get evidence for the part the client no longer runs.
DISA Module 6 treats cloud as one of six emerging technologies. It borrows NIST's definition and frames the audit around governance, third-party management, legal compliance and the right to audit. This page follows the same frame, with the current regulatory position for Indian banks added.
You save ₹450
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
The NIST Vocabulary You Need
NIST SP 800-145 (September 2011) is the definition ICAI's material quotes. It has five essential characteristics, three service models and four deployment models.
- Essential characteristics
- On-demand self-service, broad network access, resource pooling, rapid elasticity and measured service. ICAI's material notes that ISO/IEC 17788 lists six, adding multi-tenancy (several customers sharing the same pool, isolated from one another) as distinct from resource pooling.
- IaaS (Infrastructure as a Service)
- The provider supplies processing, storage and network. The customer manages the operating system, middleware, applications and data.
- PaaS (Platform as a Service)
- The provider also runs the operating system and runtime. The customer deploys and controls its own applications and data on that platform.
- SaaS (Software as a Service)
- The provider runs the application itself. The customer controls little beyond user access, some configuration settings and its own data.
- Deployment models
- Private (one organisation), community (a group with shared concerns), public (open to the general public) and hybrid (two or more of these bound together).
Who Owns Which Control
A simplified split. The contract and the provider's documentation decide the real line for each engagement.
Physical data centre security
IaaS
Provider
PaaS
Provider
SaaS
Provider
Operating system patching
IaaS
Customer
PaaS
Provider
SaaS
Provider
Application change management
IaaS
Customer
PaaS
Customer
SaaS
Provider
User access provisioning and review
IaaS
Customer
PaaS
Customer
SaaS
Customer
Data classification and backup decisions
IaaS
Customer
PaaS
Customer
SaaS
Customer (provider executes)
Logging of customer activity
IaaS
Shared
PaaS
Shared
SaaS
Shared
| Control area | IaaS | PaaS | SaaS |
|---|---|---|---|
| Physical data centre security | Provider | Provider | Provider |
| Operating system patching | Customer | Provider | Provider |
| Application change management | Customer | Customer | Provider |
| User access provisioning and review | Customer | Customer | Customer |
| Data classification and backup decisions | Customer | Customer | Customer (provider executes) |
| Logging of customer activity | Shared | Shared | Shared |
An Audit Approach That Works
- 1
Start from the contract
Read the master agreement, SLA and any data processing terms. Look for a right-to-audit clause, data location, sub-contractor rules, incident notification duties and exit provisions. ICAI's material lists right to audit and service transition planning among the governance essentials.
- 2
Map the shared responsibility line
For each key control in your risk and control matrix, record who performs it. Gaps usually appear in the shared rows: logging, key management and access reviews.
- 3
Use independent assurance for the provider side
You will rarely inspect a hyperscaler's data centre. ICAI's material points to SSAE 18 SOC 1 and SOC 2 reports, ISO 27001 certification and the Cloud Security Alliance's STAR registry. Check the report's period, scope and the complementary user entity controls it expects the customer to run.
- 4
Test the customer side directly
Identity and access management in the cloud console, privileged role assignments, configuration baselines, encryption settings and the client's own change process. A mid-size company on a SaaS ERP still owns who gets the 'post journal' role.
- 5
Check exit and continuity
Can the client get its data back in a usable format, within what time, and is that tested? Lock-in is a business continuity risk, not only a commercial one.
Quick practice on audit concepts. No signup.
Indian Banks: the 2026 Position
RBI's Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions for commercial banks, dated 31 July 2026, require a documented approach to vulnerability assessment and penetration testing that also covers the bank's information systems hosted in a cloud environment. The DISA 3.0 material predates these Directions, so expect it to discuss cloud risk without citing them.
How the DISA Assessment Test Tests This
No ICAI question bank is public, so this is drawn from the syllabus and the definitions themselves.
- check_circleModel identification: a short scenario (a developer deploying code without managing servers) and four options; PaaS is the answer. The trap is picking IaaS because servers are mentioned.
- check_circleResponsibility: 'Who is responsible for user access in SaaS?' The customer. Candidates who think SaaS outsources everything choose the provider.
- check_circleCharacteristic matching: a description of paying only for what is used maps to measured service, not rapid elasticity.
- check_circleAssurance: which report gives an auditor comfort on a service provider's controls. A SOC report, with the caveat that its scope and period must match your reliance.
FAQs
How do you audit a cloud service provider?expand_more
Mostly indirectly. Rely on independent assurance (SOC reports, ISO 27001 certification) for the provider's controls, check the contract for a right to audit, and test the controls the customer still operates, such as access, configuration and data backup.
What are the 5 characteristics of cloud computing?expand_more
Per NIST SP 800-145: on-demand self-service, broad network access, resource pooling, rapid elasticity and measured service.
Who is responsible for security in SaaS?expand_more
Both. The provider secures the infrastructure and application; the customer remains responsible for its users, access rights, the data it puts in, and configuration choices.
Is a SOC 2 report enough for a cloud audit?expand_more
Not on its own. Check that it covers the services and period you rely on, read the exceptions, and test the complementary user entity controls it assumes the customer performs.
Next steps
Take a full DISA mock testAssessment Test format, timed and scored.
