Methods of Cloud Environment Security Audit in Payment Industry Companies

Authors

  • Njoku Janet Chidinma

Keywords:

cloud security audit, payment industry, PCI DSS, fintech cybersecurity, vulnerability assessment, penetration testing, cloud compliance, CSA CCM, security governance, operational resilience

Abstract

Cloud infrastructures used by payment companies require audit methods that connect technical control testing with transaction continuity, cardholder data protection, fraud exposure, and regulatory evidence. The article develops an analytical model for assessing cloud environments in payment organizations without experimental measurement or disclosure of internal incidents. The research aim is to classify audit methods suitable for payment companies and explain how technical testing, compliance review, and risk governance form one audit cycle. The source base consists of recent academic studies, payment security reports, and recognized frameworks, including PCI DSS, CSA CCM, CIS Controls, NIST SP 800-53, OWASP WSTG, and ISO/IEC 27017. Comparative analysis, source analysis, typologization, and conceptual synthesis were applied. The article proposes an audit sequence that links cloud configuration review, control mapping, penetration testing, vulnerability assessment, evidence validation, remediation tracking, and GRC reporting. The proposed model gives payment organizations a practical way to align cloud security work with regulated operations.

Author Biography

  • Njoku Janet Chidinma

    Lagos, Nigeria, Associate, Information security officer (GRC), Multigate Payment Limited

References

[1]. AlBenJasim, S., Dargahi, T., Takruri, H., & Al-Zaidi, R. (2024). Fintech cybersecurity challenges and regulations: Bahrain case study. Journal of Computer Information Systems, 64(6), 835–851. https://doi.org/10.1080/08874417.2023.2251455

[2]. European Payments Council. (2024). 2024 payment threats and fraud trends report (EPC162-24, Version 1.0). https://www.europeanpaymentscouncil.eu/sites/default/files/kb/file/2024-12/EPC162-24%20v1.0%202024%20Payments%20Threats%20and%20Fraud%20Trends%20Report_0.pdf

[3]. PCI Security Standards Council. (2024). Payment Card Industry Data Security Standard: Requirements and testing procedures (Version 4.0.1). https://www.pcisecuritystandards.org/document_library

[4]. Chauhan, M., & Shiaeles, S. (2023). An analysis of cloud security frameworks, problems and proposed solutions. Network, 3(3), 422–450. https://doi.org/10.3390/network3030018

[5]. Cloud Security Alliance. (2021). Cloud controls matrix (Version 4.0). https://cloudsecurityalliance.org/artifacts/cloud-controls-matrix-v4

[6]. Center for Internet Security. (2024). CIS critical security controls (Version 8.1). https://www.cisecurity.org/controls/v8-1

[7]. Joint Task Force Interagency Working Group. (2020). Security and privacy controls for information systems and organizations. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-53r5

[8]. OWASP Foundation. (n.d.). Web security testing guide (Version 4.2). https://owasp.org/www-project-web-security-testing-guide/stable/

[9]. ISO/IEC. (2015). ISO/IEC 27017:2015 information technology—security techniques—code of practice for information security controls based on ISO/IEC 27002 for cloud services. https://www.iso.org/standard/43757.html

[10]. Tran-Truong, P. T., Pham, M. Q., Son, H. X., Nguyen, D. L. T., Nguyen, M. B., Tran, K. L., Van, L. C. P., Le, K. T., Vo, K. H., Kim, N. N. T., Nguyen, T. M., & Nguyen, A. T. (2025). A systematic review of multi-factor authentication in digital payment systems: NIST standards alignment and industry implementation analysis. Journal of Systems Architecture, 162, 103402. https://doi.org/10.1016/j.sysarc.2025.103402

[11]. Cremer, F., Sheehan, B., Fortmann, M., Kia, A. N., Mullins, M., Murphy, F., & Materne, S. (2022). Cyber risk and cybersecurity: A systematic review of data availability. The Geneva Papers on Risk and Insurance - Issues and Practice, 47(3), 698–736. https://doi.org/10.1057/s41288-022-00266-6

[12]. Dawood, M., Tu, S., Xiao, C., Alasmary, H., Waqas, M., & Rehman, S. U. (2023). Cyberattacks and security of cloud computing: A complete guideline. Symmetry, 15(11), 1981. https://doi.org/10.3390/sym15111981

Downloads

Published

2026-08-10

Issue

Section

Articles

How to Cite

Njoku Janet Chidinma. (2026). Methods of Cloud Environment Security Audit in Payment Industry Companies. International Journal of Computer (IJC), 57(1), 573-584. https://www.ijcjournal.org/InternationalJournalOfComputer/article/view/2560