nerdexam
Isaca

CCAK · Question #109

Supply chain agreements between CSP and cloud customers should, at minimum, include:

The correct answer is C. Audits, assessments and independent verification of compliance certifications with agreement. Supply chain agreements must include accountability mechanisms that allow cloud customers to verify the CSP is actually meeting its security and compliance commitments. Independent audits, third-party assessments, and compliance certifications (e.g., SOC 2 Type II reports, ISO…

Cloud Auditing Basics and Tools

Question

Supply chain agreements between CSP and cloud customers should, at minimum, include:

Options

  • AOrganization chart of the CSP
  • BPolicies and procedures of the cloud customer
  • CAudits, assessments and independent verification of compliance certifications with agreement
  • DRegulatory guidelines impacting the cloud customer

How the community answered

(27 responses)
  • B
    4% (1)
  • C
    93% (25)
  • D
    4% (1)

Explanation

Supply chain agreements must include accountability mechanisms that allow cloud customers to verify the CSP is actually meeting its security and compliance commitments. Independent audits, third-party assessments, and compliance certifications (e.g., SOC 2 Type II reports, ISO 27001, PCI DSS attestations) provide the evidence needed to validate CSP claims. Without this, customers are trusting the CSP on its word alone. The other options are either not minimum requirements or belong outside the agreement scope: an org chart (A) is informational, the customer's own policies (B) govern the customer not the vendor, and regulatory guidelines (D) are external mandates that exist regardless of any agreement.

Topics

#Cloud agreements#CSP assurance#Compliance verification#Auditing clauses

Community Discussion

No community discussion yet for this question.

Full CCAK Practice