CCSK Legal, Compliance, and Audit in Cloud 2 — Questions and Answers
Question 1: What does the GDPR require of cloud customers regarding data processing by cloud providers?
- Cloud providers are automatically the data controller for all stored data
- Customers must enter into Data Processing Agreements (DPAs) with cloud providers who process EU personal data on their behalf (Correct answer)
- GDPR does not apply to data processed in cloud environments
- Customers must store all EU personal data only in on-premises systems
Correct answer: Customers must enter into Data Processing Agreements (DPAs) with cloud providers who process EU personal data on their behalf
GDPR requires data controllers (customers) to have DPAs with processors (cloud providers) ensuring the provider handles EU personal data per GDPR requirements.
Question 2: What is a 'SOC 2 Type II' report and why is it relevant to CCSK cloud security assessments?
- A report that certifies cloud providers have zero security vulnerabilities
- An independent auditor's report verifying a cloud provider's security controls operated effectively over a defined period (typically 12 months) (Correct answer)
- A one-time snapshot audit of a provider's security configuration
- A financial audit of cloud provider billing practices
Correct answer: An independent auditor's report verifying a cloud provider's security controls operated effectively over a defined period (typically 12 months)
SOC 2 Type II covers operational effectiveness of controls over time (vs. Type I which is point-in-time), providing stronger assurance of consistent security practices.
Question 3: According to CCSK, what is 'regulatory arbitrage' in cloud computing and why is it a concern?
- Using cloud services to reduce costs while maintaining compliance
- Storing data in jurisdictions with weaker privacy laws to avoid stricter regulations, undermining compliance intent (Correct answer)
- Negotiating regulatory requirements with cloud providers during contract review
- Applying multiple regulatory frameworks simultaneously to cloud workloads
Correct answer: Storing data in jurisdictions with weaker privacy laws to avoid stricter regulations, undermining compliance intent
Regulatory arbitrage exploits jurisdictional differences by storing data where regulations are weakest, which may violate the intent of regulations in the customer's home jurisdiction.
Question 4: What is 'ISO/IEC 27017' and how does it differ from ISO/IEC 27001 in cloud security?
- They are identical standards with different numbering
- ISO 27017 provides cloud-specific security controls extending ISO 27001, addressing cloud-unique risks like virtual environments and shared infrastructure (Correct answer)
- ISO 27017 is for network security; ISO 27001 is for cloud security
- ISO 27017 replaces ISO 27001 for cloud service providers
Correct answer: ISO 27017 provides cloud-specific security controls extending ISO 27001, addressing cloud-unique risks like virtual environments and shared infrastructure
ISO 27017 extends the ISO 27001 framework with additional controls specific to cloud services, covering topics like virtual machines, provider-customer responsibilities, and asset ownership.
Question 5: What does CCSK say about the handling of 'personally identifiable information' (PII) in cloud audit logs?
- PII in audit logs is exempt from privacy regulations because it serves security purposes
- Audit logs containing PII must be protected with the same controls as other sensitive data, and retention periods must comply with privacy regulations (Correct answer)
- PII should be removed from all cloud logs to simplify compliance
- Cloud providers are responsible for all PII in logs they generate
Correct answer: Audit logs containing PII must be protected with the same controls as other sensitive data, and retention periods must comply with privacy regulations
Audit logs often contain PII (usernames, IP addresses, access details) and must be protected, access-controlled, and retained per applicable privacy and compliance requirements.
Question 6: According to CCSK, what is 'contractual security requirements' in cloud vendor management?
- Requirements the vendor must meet to receive payment
- Explicit security obligations written into cloud contracts covering data protection, breach notification, audit rights, and compliance (Correct answer)
- Requirements for the customer's security team when using cloud services
- Minimum hardware specifications the provider must maintain
Correct answer: Explicit security obligations written into cloud contracts covering data protection, breach notification, audit rights, and compliance
Contractual security requirements formalize provider security obligations, ensuring accountability for data protection, incident notification, and compliance support.
What does the GDPR require of cloud customers regarding data processing by cloud providers?