nerdexam
Isaca

CCAK · Question #115

Which of the following is the BEST tool to perform cloud security control audits?

The correct answer is D. CSA Cloud Control Matrix (CCM). The CSA Cloud Control Matrix (CCM) is specifically engineered as a cloud-native control framework and audit tool. It covers 17 domains relevant to cloud security (e.g., IAM, infrastructure security, data security, incident response) and provides control objectives that map to…

Cloud Security Auditing

Question

Which of the following is the BEST tool to perform cloud security control audits?

Options

  • AGeneral Data Protection Regulation (GDPR)
  • BISO 27001
  • CFederal Information Processing Standard (FIPS) 140-2
  • DCSA Cloud Control Matrix (CCM)

How the community answered

(42 responses)
  • A
    5% (2)
  • B
    2% (1)
  • C
    5% (2)
  • D
    88% (37)

Explanation

The CSA Cloud Control Matrix (CCM) is specifically engineered as a cloud-native control framework and audit tool. It covers 17 domains relevant to cloud security (e.g., IAM, infrastructure security, data security, incident response) and provides control objectives that map to major regulations and standards. GDPR (A) is a data privacy regulation, not an audit tool. ISO 27001 (B) is an information security management standard applicable broadly to IT, not cloud-specific. FIPS 140-2 (C) is a US government standard for cryptographic module validation, not a broad cloud audit framework. The CCM was designed precisely for evaluating cloud service provider and cloud customer security posture.

Topics

#Cloud Security Auditing#CSA CCM#Security Controls#Audit Tools

Community Discussion

No community discussion yet for this question.

Full CCAK Practice