nerdexam
Isaca

CCAK · Question #123

Which of the following is MOST important to consider when an organization is building a compliance program for the cloud?

The correct answer is A. The rapidly changing service portfolio and architecture of the cloud. Cloud compliance programs must above all account for the rapid pace of change in cloud service portfolios and architectures, which continuously introduces new risks and can invalidate existing controls between assessment cycles.

Cloud Compliance

Question

Which of the following is MOST important to consider when an organization is building a compliance program for the cloud?

Options

  • AThe rapidly changing service portfolio and architecture of the cloud.
  • BCloud providers should not be part of the compliance program.
  • CThe fairly static nature of the service portfolio and architecture of the cloud.
  • DThe cloud is similar to the on-premise environment in terms of compliance.

How the community answered

(25 responses)
  • A
    88% (22)
  • B
    8% (2)
  • D
    4% (1)

Why each option

Cloud compliance programs must above all account for the rapid pace of change in cloud service portfolios and architectures, which continuously introduces new risks and can invalidate existing controls between assessment cycles.

AThe rapidly changing service portfolio and architecture of the cloud.Correct

Cloud providers frequently release new services, deprecate existing ones, and update underlying architectures, meaning the risk landscape can shift materially between compliance review cycles. An effective cloud compliance program must therefore be designed with dynamic review processes, continuous monitoring, and rapid control update mechanisms to remain aligned with the actual cloud environment - unlike static on-premises compliance frameworks that operate on longer, more predictable change cycles.

BCloud providers should not be part of the compliance program.

Cloud providers must be included in a compliance program because they control significant portions of the environment under assessment; excluding them leaves critical shared-responsibility obligations unaddressed.

CThe fairly static nature of the service portfolio and architecture of the cloud.

Cloud service portfolios and architectures are among the most rapidly changing technology environments, making this characterization factually incorrect and a dangerous assumption on which to build a compliance program.

DThe cloud is similar to the on-premise environment in terms of compliance.

The cloud differs substantially from on-premises environments through multi-tenancy, dynamic provisioning, and the shared responsibility model, making direct application of on-premises compliance approaches inadequate.

Concept tested: Dynamic cloud environment impact on compliance program design

Source: https://cloudsecurityalliance.org/research/cloud-controls-matrix/

Topics

#Cloud compliance program#Cloud characteristics#Dynamic environment#Service portfolio changes

Community Discussion

No community discussion yet for this question.

Full CCAK Practice