CCAK · Question #115
Which of the following is the BEST tool to perform cloud security control audits?
The correct answer is D. CSA Cloud Control Matrix (CCM). The CSA Cloud Control Matrix (CCM) is specifically engineered as a cloud-native control framework and audit tool. It covers 17 domains relevant to cloud security (e.g., IAM, infrastructure security, data security, incident response) and provides control objectives that map to…
Question
Which of the following is the BEST tool to perform cloud security control audits?
Options
- AGeneral Data Protection Regulation (GDPR)
- BISO 27001
- CFederal Information Processing Standard (FIPS) 140-2
- DCSA Cloud Control Matrix (CCM)
How the community answered
(42 responses)- A5% (2)
- B2% (1)
- C5% (2)
- D88% (37)
Explanation
The CSA Cloud Control Matrix (CCM) is specifically engineered as a cloud-native control framework and audit tool. It covers 17 domains relevant to cloud security (e.g., IAM, infrastructure security, data security, incident response) and provides control objectives that map to major regulations and standards. GDPR (A) is a data privacy regulation, not an audit tool. ISO 27001 (B) is an information security management standard applicable broadly to IT, not cloud-specific. FIPS 140-2 (C) is a US government standard for cryptographic module validation, not a broad cloud audit framework. The CCM was designed precisely for evaluating cloud service provider and cloud customer security posture.
Topics
Community Discussion
No community discussion yet for this question.