CONVERGENCE OR CHAOS? THE IMPACT OF SASE ON LEGACY GRC FRAMEWORKS

Fuente: Zenodo
Salvato in:
Dettagli Bibliografici
Autore principale: Ankit Verma
Natura: Recurso digital
Pubblicazione: Zenodo 2023
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866901952011436032
author Ankit Verma
author_facet Ankit Verma
contents <p><a href="https://ijetrm.com/issues/files/Jan-2023-14-1768362064-OCT202312.pdf">Secure Access Service Edge (SASE)</a> as an emerging solution to enterprise security and networking platforms is a<br>critical change which has been necessitated by the need to accommodate distributed users, cloud-native applications<br>and dynamic access demands. Although SASE is an architectural convergence, which implies the delivery of<br>networking and security services as part of the same cloud-based system, the question of what it means to the<br>existing Governance, Risk, and Compliance (GRC) framework is not well-studied. The conventional GRC models<br>were developed upon infrastructures, distinct boundaries, and regular checks on compliance, which are becoming<br>more and more incompatible with steady and distributed SASE environments.<br>This paper evaluates the claims of governance convergence or organizational mayhem about the adoption of SASE<br>using the analysis of its effects on traditional GRC models. The research explores the reconstruction of risk<br>visibility, ownership of control, auditability and compliance assurance through SASE. The paper finds main areas in<br>which the misfit between SASE architectures and conventional GRC practices is evident through a systematic<br>conceptual analysis, and in what circumstances SASE is able to increase the effectiveness of governance. These<br>findings indicate that in the absence of a specific adjustment of GRC processes, SASE can contribute to governance<br>fragmentation; nevertheless, when adjusted to the continued and metrics-driven models of governance, SASE can<br>serve as a driver of integrated and adaptive GRC in contemporary businesses.</p>
format Recurso digital
id zenodo_https___doi_org_10_5281_zenodo_18238948
institution Zenodo
language
publishDate 2023
publisher Zenodo
record_format zenodo
spellingShingle CONVERGENCE OR CHAOS? THE IMPACT OF SASE ON LEGACY GRC FRAMEWORKS
Ankit Verma
Secure Access Service Edge (SASE); Governance, Risk, and Compliance (GRC); Cloud Security Architecture; Zero Trust; Continuous Compliance; Enterprise Risk Management
<p><a href="https://ijetrm.com/issues/files/Jan-2023-14-1768362064-OCT202312.pdf">Secure Access Service Edge (SASE)</a> as an emerging solution to enterprise security and networking platforms is a<br>critical change which has been necessitated by the need to accommodate distributed users, cloud-native applications<br>and dynamic access demands. Although SASE is an architectural convergence, which implies the delivery of<br>networking and security services as part of the same cloud-based system, the question of what it means to the<br>existing Governance, Risk, and Compliance (GRC) framework is not well-studied. The conventional GRC models<br>were developed upon infrastructures, distinct boundaries, and regular checks on compliance, which are becoming<br>more and more incompatible with steady and distributed SASE environments.<br>This paper evaluates the claims of governance convergence or organizational mayhem about the adoption of SASE<br>using the analysis of its effects on traditional GRC models. The research explores the reconstruction of risk<br>visibility, ownership of control, auditability and compliance assurance through SASE. The paper finds main areas in<br>which the misfit between SASE architectures and conventional GRC practices is evident through a systematic<br>conceptual analysis, and in what circumstances SASE is able to increase the effectiveness of governance. These<br>findings indicate that in the absence of a specific adjustment of GRC processes, SASE can contribute to governance<br>fragmentation; nevertheless, when adjusted to the continued and metrics-driven models of governance, SASE can<br>serve as a driver of integrated and adaptive GRC in contemporary businesses.</p>
title CONVERGENCE OR CHAOS? THE IMPACT OF SASE ON LEGACY GRC FRAMEWORKS
topic Secure Access Service Edge (SASE); Governance, Risk, and Compliance (GRC); Cloud Security Architecture; Zero Trust; Continuous Compliance; Enterprise Risk Management
url https://doi.org/10.5281/zenodo.18238948