| Text of Recommendation | Develop and implement policies, procedures, and standards that are consistent with the NCUA’s cloud computing strategy and address, at minimum, the following:
• Coordination, identification, and clarification of responsibilities and processes across all stakeholders for IT service contract reviews, service level agreements alignment and monitoring, and cloud service incident management.
• Specific criterion for the prioritization, selection, and use of cloud computing services.
• Periodic review of contract clauses included for cloud computing services to confirm documentation supporting security requirements are
clearly identified to the vendor and security and operational risks are appropriately managed. |
|---|---|
| Recommendation Number | OIG-24-02 |
| Recommendation Status | Open |
| Significant Recommendation | No |
| Recommendation Questioned Costs | $0 |
| Recommendation Funds for Better Use | $0 |
| Additional Details Link |
| Submitting OIG | |
|---|---|
| Linked Report |
