The latest enterprise risk management news from around the world

Australian Prudential Regulation Authority issues shared computing services outsourcing advice

The Australian Prudential Regulation Authority (APRA) has released an information paper on prudential considerations and key principles in relation to outsourcing involving shared computing services, including cloud.

The information paper uses the term ‘shared computing services’ (whether labelled cloud or otherwise) to differentiate arrangements which involve the sharing of IT assets (including hardware, software and/or data storage) with other parties, from those where IT assets are dedicated to a single entity.

The use of shared computing services by APRA regulated entities is expected to continually evolve, along with the maturity of the risk management and mitigation techniques applied. APRA therefore encourages ongoing dialogue with industry participants to ensure prudent practices are in place and risks are adequately mitigated when regulated entities seek the advantages that shared computing services may realise.

While shared computing services may bring benefits, such as economies of scale, they also bring associated risks. These can vary considerably depending on the particular usage. Low risk usages are those involving IT assets with low criticality and sensitivity. Other usages involve heightened risk, such as the exposure of highly critical and/or highly sensitive IT assets to ‘un-trusted’ environments, necessitating a greater degree of caution and supervisory interest. For these arrangements, APRA encourages prior consultation.

The information paper also discusses weaknesses that APRA has identified as part of its ongoing supervisory activities, reflecting that risk management and mitigation techniques are yet to fully mature in this area. In particular, it is not readily evident that ‘public cloud’ arrangements have reached a level of maturity commensurate with usages having an extreme impact if disrupted.

Usages having an extreme impact if disrupted include, in particular, hosting systems of record holding information essential to determining obligations to customers (such as customer identity, current balance/benefits and transaction history).

Obtain the information paper from here.



Want news and features emailed to you?

Signup to our free newsletters and never miss a story.

A website you can trust

The entire Continuity Central website is scanned daily by Sucuri to ensure that no malware exists within the site. This means that you can browse with complete confidence.

Business continuity?

Business continuity can be defined as 'the processes, procedures, decisions and activities to ensure that an organization can continue to function through an operational interruption'. Read more about the basics of business continuity here.

Get the latest news and information sent to you by email

Continuity Central provides a number of free newsletters which are distributed by email. To subscribe click here.