nerdexam
Isaca

CCAK · Question #37

Which of the following is the MOST feasible way to validate the performance of CSPs for the delivery of technology resources?

The correct answer is D. Service organization controls report. A Service Organization Controls (SOC) report - particularly SOC 2 Type II - is the industry-standard mechanism for validating how a CSP manages and protects data and technology resources. It is produced by an independent third-party auditor and documents the CSP's controls…

Cloud Auditing Basics and Tools

Question

Which of the following is the MOST feasible way to validate the performance of CSPs for the delivery of technology resources?

Options

  • ACloud compliance program
  • BLegacy IT compliance program
  • CInternal audit program
  • DService organization controls report

How the community answered

(57 responses)
  • A
    2% (1)
  • C
    4% (2)
  • D
    95% (54)

Explanation

A Service Organization Controls (SOC) report - particularly SOC 2 Type II - is the industry-standard mechanism for validating how a CSP manages and protects data and technology resources. It is produced by an independent third-party auditor and documents the CSP's controls, their design, and their operational effectiveness over a defined period. It is more feasible than direct audits because customers typically cannot audit CSPs themselves. Cloud compliance programs and legacy IT compliance programs focus on the customer side, and internal audits cannot objectively assess a third-party CSP's controls.

Topics

#CSP performance validation#Third-party assurance#SOC reports#Cloud auditing tools

Community Discussion

No community discussion yet for this question.

Full CCAK Practice