CONVERGENCE OR CHAOS? THE IMPACT OF SASE ON LEGACY GRC FRAMEWORKS
Fuente:
Zenodo
Salvato in:
| Autore principale: | |
|---|---|
| Natura: | Recurso digital |
| Pubblicazione: |
Zenodo
2023
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
| _version_ | 1866901952011436032 |
|---|---|
| author | Ankit Verma |
| author_facet | Ankit Verma |
| contents | <p><a href="https://ijetrm.com/issues/files/Jan-2023-14-1768362064-OCT202312.pdf">Secure Access Service Edge (SASE)</a> as an emerging solution to enterprise security and networking platforms is a<br>critical change which has been necessitated by the need to accommodate distributed users, cloud-native applications<br>and dynamic access demands. Although SASE is an architectural convergence, which implies the delivery of<br>networking and security services as part of the same cloud-based system, the question of what it means to the<br>existing Governance, Risk, and Compliance (GRC) framework is not well-studied. The conventional GRC models<br>were developed upon infrastructures, distinct boundaries, and regular checks on compliance, which are becoming<br>more and more incompatible with steady and distributed SASE environments.<br>This paper evaluates the claims of governance convergence or organizational mayhem about the adoption of SASE<br>using the analysis of its effects on traditional GRC models. The research explores the reconstruction of risk<br>visibility, ownership of control, auditability and compliance assurance through SASE. The paper finds main areas in<br>which the misfit between SASE architectures and conventional GRC practices is evident through a systematic<br>conceptual analysis, and in what circumstances SASE is able to increase the effectiveness of governance. These<br>findings indicate that in the absence of a specific adjustment of GRC processes, SASE can contribute to governance<br>fragmentation; nevertheless, when adjusted to the continued and metrics-driven models of governance, SASE can<br>serve as a driver of integrated and adaptive GRC in contemporary businesses.</p> |
| format | Recurso digital |
| id | zenodo_https___doi_org_10_5281_zenodo_18238948 |
| institution | Zenodo |
| language | |
| publishDate | 2023 |
| publisher | Zenodo |
| record_format | zenodo |
| spellingShingle | CONVERGENCE OR CHAOS? THE IMPACT OF SASE ON LEGACY GRC FRAMEWORKS Ankit Verma Secure Access Service Edge (SASE); Governance, Risk, and Compliance (GRC); Cloud Security Architecture; Zero Trust; Continuous Compliance; Enterprise Risk Management <p><a href="https://ijetrm.com/issues/files/Jan-2023-14-1768362064-OCT202312.pdf">Secure Access Service Edge (SASE)</a> as an emerging solution to enterprise security and networking platforms is a<br>critical change which has been necessitated by the need to accommodate distributed users, cloud-native applications<br>and dynamic access demands. Although SASE is an architectural convergence, which implies the delivery of<br>networking and security services as part of the same cloud-based system, the question of what it means to the<br>existing Governance, Risk, and Compliance (GRC) framework is not well-studied. The conventional GRC models<br>were developed upon infrastructures, distinct boundaries, and regular checks on compliance, which are becoming<br>more and more incompatible with steady and distributed SASE environments.<br>This paper evaluates the claims of governance convergence or organizational mayhem about the adoption of SASE<br>using the analysis of its effects on traditional GRC models. The research explores the reconstruction of risk<br>visibility, ownership of control, auditability and compliance assurance through SASE. The paper finds main areas in<br>which the misfit between SASE architectures and conventional GRC practices is evident through a systematic<br>conceptual analysis, and in what circumstances SASE is able to increase the effectiveness of governance. These<br>findings indicate that in the absence of a specific adjustment of GRC processes, SASE can contribute to governance<br>fragmentation; nevertheless, when adjusted to the continued and metrics-driven models of governance, SASE can<br>serve as a driver of integrated and adaptive GRC in contemporary businesses.</p> |
| title | CONVERGENCE OR CHAOS? THE IMPACT OF SASE ON LEGACY GRC FRAMEWORKS |
| topic | Secure Access Service Edge (SASE); Governance, Risk, and Compliance (GRC); Cloud Security Architecture; Zero Trust; Continuous Compliance; Enterprise Risk Management |
| url | https://doi.org/10.5281/zenodo.18238948 |