nerdexam
Isaca

CCAK · Question #33

Which of the following has the MOST substantial impact on how aggressive or conservative the cloud approach of an organization will be?

The correct answer is C. Applicable laws and regulations. Applicable laws and regulations are external, mandatory constraints that organizations must comply with regardless of their internal preferences, budgets, or risk appetite. Regulations such as GDPR, HIPAA, PCI DSS, or FedRAMP can prohibit certain cloud deployment models, data…

Cloud Compliance

Question

Which of the following has the MOST substantial impact on how aggressive or conservative the cloud approach of an organization will be?

Options

  • AInternal policies and technical standards
  • BRisk scoring criteria
  • CApplicable laws and regulations
  • DRisk appetite and budget constraints

How the community answered

(20 responses)
  • A
    10% (2)
  • B
    15% (3)
  • C
    70% (14)
  • D
    5% (1)

Explanation

Applicable laws and regulations are external, mandatory constraints that organizations must comply with regardless of their internal preferences, budgets, or risk appetite. Regulations such as GDPR, HIPAA, PCI DSS, or FedRAMP can prohibit certain cloud deployment models, data residency arrangements, or vendor relationships - directly forcing organizations to adopt a conservative cloud approach. Internal factors like policies, budget, and risk scoring can be adjusted internally, but legal and regulatory requirements impose non-negotiable boundaries. They have the most substantial impact because non-compliance carries legal liability, fines, and reputational damage.

Topics

#Cloud Strategy#Regulatory Compliance#Risk Management#Cloud Governance

Community Discussion

No community discussion yet for this question.

Full CCAK Practice