TITLE:
From Cloud Security Alerts to Audit-Ready Evidence: A Risk-Based GRC Framework for Cyber Assurance in Australia
AUTHORS:
Parisasadat Shojaei, Rezza Moieni
KEYWORDS:
Cloud Security Posture Management, Governance, Risk and Compliance, Cyber Assurance, Audit Evidence, Cloud Security, Risk-Based Prioritisation, Australia, Continuous Monitoring
JOURNAL NAME:
Open Journal of Social Sciences,
Vol.14 No.8,
August
12,
2026
ABSTRACT: Cloud security posture management (CSPM), vulnerability management, and cloud-native security services generate large volumes of findings about misconfiguration, vulnerable workloads, weak identity controls, public exposure, encryption gaps, and logging deficiencies. These findings are valuable for security operations, but they often remain difficult for governance, risk, compliance (GRC), audit, and management stakeholders to interpret, prioritise, and evidence. This paper proposes Cloud Alert-to-Governance Evidence (CAGE), a practical risk-based framework for converting cloud security findings into governance-ready artefacts. CAGE classifies each finding through five linked dimensions: technical severity, asset criticality, exposure context, business impact, and compliance relevance. It then connects prioritised risks to control mappings, treatment decisions, accountable owners, remediation evidence, exception records, residual risk status, and audit-ready reporting. The framework is developed through conceptual design and standards synthesis, drawing on cloud security literature, continuous monitoring guidance, risk assessment concepts, Australian cyber guidance, and recognised frameworks including the Australian Essential Eight, ISO/IEC 27001, ISO/IEC 27005, NIST SP 800-30, NIST SP 800-137, NIST Cybersecurity Framework 2.0, and the Cloud Security Alliance Cloud Controls Matrix. The paper strengthens the framework by adding a comparative validation table, an illustrative worked example, and an Australian workforce relevance section. The contribution is a structured bridge between cloud security operations and cyber assurance practice. The framework is conceptual and practice-oriented; it does not claim empirical validation. Future work should evaluate CAGE using real organisational cloud findings and practitioner review in Australian industry contexts.