nerdexam
Isaca

CCAK · Question #23

In which control should a cloud service provider, upon request, inform customers of compliance impact and risk, especially if customer data is used as part of the services?

The correct answer is A. Service Provider control. Within the CSA Cloud Controls Matrix (CCM), the obligation for a CSP to inform customers about compliance impacts and risks - particularly when customer data is involved in service delivery - falls under the Service Provider controls domain. This domain governs what the CSP…

Cloud Compliance

Question

In which control should a cloud service provider, upon request, inform customers of compliance impact and risk, especially if customer data is used as part of the services?

Options

  • AService Provider control
  • BImpact and Risk control
  • CData Inventory control
  • DCompliance control

How the community answered

(41 responses)
  • A
    88% (36)
  • B
    2% (1)
  • C
    2% (1)
  • D
    7% (3)

Explanation

Within the CSA Cloud Controls Matrix (CCM), the obligation for a CSP to inform customers about compliance impacts and risks - particularly when customer data is involved in service delivery - falls under the Service Provider controls domain. This domain governs what the CSP must disclose, communicate, and make available to customers regarding how services are operated, what risks exist, and how compliance obligations are managed. CSPs must be transparent with their customers about the regulatory and risk landscape affecting the services they consume, especially when customer data is processed or used as part of the service.

Topics

#CSP responsibilities#Customer communication#Compliance impact#Risk reporting

Community Discussion

No community discussion yet for this question.

Full CCAK Practice