CloudAudit and the Automated Audit, Assertion, Assessment, and Assurance API (A6)

The goal of CloudAudit (codename: A6) is to provide a common interface and namespace that allows cloud computing providers to automate the Audit, Assertion, Assessment, and Assurance (A6) of their infrastructure (IaaS), platform (PaaS), and application (SaaS) environments and allow authorized consumers of their services to do likewise via an open, extensible and secure interface and methodology.

Our execution mantra is to:
  • Keep it simple, lightweight and easy to implement; offer primitive definitions & language structure using HTTP(S)
  • Allow for extension and elaboration by providers and choice of trusted assertion validation sources, checklist definitions, etc.
  • Not require adoption of other platform-specific APIs
  • Provide interfaces to Cloud naming and registry services
CloudAudit is a volunteer cross-industry effort from the best minds and talent in Cloud, networking, security, audit, assurance and architecture backgrounds. We hope you’ll get involved, too. You can read more about the genesis of CloudAudit/A6 here.


You can also read an excellent interview from the folks at SearchCloudComputing here which is replicated on the FAQ page.
Benefits Of CloudAudit/A6

The benefits to the Cloud Service Provider are to enable the automation of typically one-off labor-intensive, repetitive and costly auditing, assurance and compliance functions and provide a controlled set of interfaces to allow for assessments by consumers of their services.

The benefits to the “consumer” of the Cloud services or their duly-authorized representatives are to provide a consistent and standardized interface to the information produced by the service provider.

We intend not to be prescriptive as to the mechanisms used to gather the data or how these interfaces are presented, but rather provide a consistent representation to the consumer and the tools they choose to utilize. There will likely be programmatic interfaces (in the classical definition of an API) but we will focus initially on representative schema and data structures mapped to existing compliance, security and assurance frameworks.

Core Team Members
There are over 250 participants/interested parties supporting CloudAudit/A6. The “core team” below are those that have committed to participate on a regular basis and establish leadership roles within the group. Anyone and everyone is welcome to contribute and participate. To join, sign up on the forums and participate in the weekly calls held Monday.





































NameAffiliation
Lew TuckerSun[shine]
Doug EganCSC
George ReeseEnstratus
Gunnar PetersonArctec
Andy EllisAkamai
Craig NelsonMicrosoft
Allwyn SequeiraVMware
Sam JohnstonGoogle
Shlomo SwidlerOrchestratus
Scott SanchezUnisys
Steve RileyAmazon Web Services
Ken OwensSavvis
Chris DrumgooleTerremark
Bret PiattRackspace Cloud
John Menerick-
Randy BiasCloudScaling
James UrquhartCisco
Background & Meetings
Here is the introduction presentation from the group call on 2/12/10:


Note: CloudAudit/A6 Working Group calls are scheduled weekly Mondays (starting 3/15/10) at 10am PST/1PM EST. Please see the Forums for dial-in information and recordings from previous calls.