Legal, Compliance, and Audit in Cloud Flashcards
6 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Legal, Compliance, and Audit in Cloud flashcards as text
What is the NIST Cybersecurity Framework (CSF) and how does it relate to CCSK?
Answer: The NIST CSF provides a risk-based framework (Identify, Protect, Detect, Respond, Recover) that complements and maps to CCSK control domains
The NIST CSF organizes cybersecurity activities into five functions that align with CCSK security domains, providing a structured approach to cloud risk management.
According to CCSK, what due diligence should organizations perform when selecting a cloud provider?
Answer: Assess the provider's security certifications, audit reports, data handling practices, SLAs, and jurisdictional data location
Cloud provider due diligence requires reviewing certifications (ISO, SOC), audit reports, security practices, contractual terms, and data residency to assess suitability for sensitive workloads.
What is 'vendor lock-in' from a security perspective in CCSK?
Answer: Dependence on proprietary cloud services that makes migration difficult, potentially forcing continued use of a provider with degraded security posture
Vendor lock-in limits options if a provider's security deteriorates; using open standards and portable architectures maintains the ability to switch providers when needed.
What does CCSK say about 'supply chain security' in the context of cloud services?
Answer: Cloud providers rely on their own supply chains (hardware, software, sub-processors) whose risks extend to customer workloads, requiring vendor risk assessment
Cloud providers use hardware vendors, software libraries, and sub-processors whose compromise could impact customer security, requiring assessment of the full supply chain.
According to CCSK, what is the purpose of 'continuous compliance monitoring' in cloud environments?
Answer: Automatically and continuously checking cloud configurations and controls against compliance requirements to detect drift in real time
Continuous compliance monitoring uses automated tools (CSPM) to detect configuration drift and policy violations in real time rather than relying on periodic manual audits.
What does CCSK identify as a key component of an effective cloud governance framework?
Answer: Defined policies, accountability structures, risk management processes, and mechanisms to verify controls across the cloud estate
Effective cloud governance requires clear policies, defined ownership, risk processes, and verification mechanisms to maintain consistent security and compliance across cloud services.