nerdexam
Isaca

CCAK · Question #125

Which of the following attestation allows for immediate adoption of the Cloud Control Matrix (CCM) as additional criteria to AICPA Trust Service Criteria and provides the flexibility to update the…

The correct answer is B. CSA STAR Attestation. CSA STAR Attestation is the only framework listed that uniquely enables immediate adoption of the CCM as additional criteria within an AICPA SOC 2 engagement and is structured to evolve as cloud technology and market requirements change.

Cloud Compliance

Question

Which of the following attestation allows for immediate adoption of the Cloud Control Matrix (CCM) as additional criteria to AICPA Trust Service Criteria and provides the flexibility to update the criteria as technology and market requirements change?

Options

  • APC-IDSS
  • BCSA STAR Attestation
  • CMTCS
  • DBSI Criteria Catalogue C5

How the community answered

(48 responses)
  • A
    4% (2)
  • B
    94% (45)
  • C
    2% (1)

Why each option

CSA STAR Attestation is the only framework listed that uniquely enables immediate adoption of the CCM as additional criteria within an AICPA SOC 2 engagement and is structured to evolve as cloud technology and market requirements change.

APC-IDSS

PCI-DSS is a payment card industry data security standard scoped to cardholder data environments and does not provide a mechanism for adopting CCM as additional AICPA-based attestation criteria.

BCSA STAR AttestationCorrect

CSA STAR Attestation was specifically designed to layer the Cloud Control Matrix on top of AICPA Trust Services Criteria within a SOC 2 Type 1 or Type 2 examination, enabling cloud-specific control coverage without requiring a separate certification process. Its additional criteria are managed by CSA and can be updated as new cloud technologies emerge or market requirements change, providing a living attestation standard rather than a fixed, immutable control set - a flexibility not offered by the other options listed.

CMTCS

MTCS (Multi-Tier Cloud Security) is a Singapore national standard for cloud service providers and does not integrate CCM as additional AICPA Trust Services Criteria or offer flexibility for market-driven criteria updates.

DBSI Criteria Catalogue C5

BSI C5 is a German Federal Office for Information Security cloud compliance catalog that defines its own baseline control set and does not incorporate CCM as additional AICPA Trust Services Criteria.

Concept tested: CSA STAR Attestation CCM integration and criteria adaptability

Source: https://cloudsecurityalliance.org/star/attestation

Topics

#CSA STAR Attestation#Cloud Control Matrix (CCM)#AICPA Trust Service Criteria#Cloud Compliance Frameworks

Community Discussion

No community discussion yet for this question.

Full CCAK Practice