nerdexam
Isaca

CCAK · Question #122

To qualify for CSA STAR attestation for a particular cloud system, the SOC 2 report must cover:

The correct answer is C. all Cloud Control Matrix (CCM) controls and TSPC security principles. CSA STAR Attestation requires the SOC 2 report to cover all Cloud Control Matrix controls combined with the AICPA Trust Services Principles Criteria, merging cloud-specific controls with the established SOC 2 assurance standard.

Cloud Compliance

Question

To qualify for CSA STAR attestation for a particular cloud system, the SOC 2 report must cover:

Options

  • AISO/I 27001: 2013 controls.
  • Bmaturity model criteria.
  • Call Cloud Control Matrix (CCM) controls and TSPC security principles.
  • DCloud Control Matrix (CCM) and ISO/IEC 27001:2013 controls.

How the community answered

(18 responses)
  • C
    94% (17)
  • D
    6% (1)

Why each option

CSA STAR Attestation requires the SOC 2 report to cover all Cloud Control Matrix controls combined with the AICPA Trust Services Principles Criteria, merging cloud-specific controls with the established SOC 2 assurance standard.

AISO/I 27001: 2013 controls.

ISO/IEC 27001:2013 controls are the basis for CSA STAR Certification, not STAR Attestation; STAR Attestation is AICPA SOC 2-based and does not mandate ISO 27001 control coverage in the report.

Bmaturity model criteria.

Maturity model criteria apply to the CSA STAR self-assessment (Level 1) and continuous monitoring (Level 3) tiers, not to the SOC 2-based STAR Attestation report requirements.

Call Cloud Control Matrix (CCM) controls and TSPC security principles.Correct

CSA STAR Attestation is built on a SOC 2 engagement in which the auditor assesses both the AICPA Trust Services Principles Criteria - at minimum the Security principle - and all Cloud Control Matrix controls as additional criteria layered on top. This dual coverage ensures the attestation addresses the general IT assurance baseline provided by AICPA and the cloud-specific control requirements defined by CSA, producing a comprehensive cloud security assurance report that satisfies both frameworks simultaneously.

DCloud Control Matrix (CCM) and ISO/IEC 27001:2013 controls.

Pairing CCM with ISO/IEC 27001:2013 controls describes the basis for CSA STAR Certification, not STAR Attestation; STAR Attestation pairs CCM with AICPA TSPC rather than ISO standards.

Concept tested: CSA STAR Attestation SOC 2 and CCM coverage requirements

Source: https://cloudsecurityalliance.org/star/attestation

Topics

#CSA STAR#SOC 2#Cloud Control Matrix#Cloud Compliance

Community Discussion

No community discussion yet for this question.

Full CCAK Practice