Text of Recommendation | Develop and implement policies, procedures, and standards that are consistent with the NCUA’s cloud computing strategy and address, at minimum, the following:
• Coordination, identification, and clarification of responsibilities and processes across all stakeholders for IT service contract reviews, service level agreements alignment and monitoring, and cloud service incident management.
• Specific criterion for the prioritization, selection, and use of cloud computing services.
• Periodic review of contract clauses included for cloud computing services to confirm documentation supporting security requirements are
clearly identified to the vendor and security and operational risks are appropriately managed. |
---|---|
Recommendation Number | OIG-24-02 |
Recommendation Status | Open |
Significant Recommendation | No |
Recommendation Questioned Costs | $0 |
Recommendation Funds for Better Use | $0 |
Additional Details Link |
Submitting OIG | |
---|---|
Linked Report |