CCAK · Question #47
One of the Cloud Control Matrix's (CCM's) control specifications states that "Independent reviews and assessments shall be performed at least annually to ensure that the organization addresses…
The correct answer is B. Information system and regulatory mapping. In the Cloud Control Matrix (CCM), the Audit Assurance and Compliance (AAC) domain's 'Information System and Regulatory Mapping' control addresses the requirement that organizations perform independent reviews and assessments at least annually to identify nonconformities with…
Question
One of the Cloud Control Matrix's (CCM's) control specifications states that "Independent reviews and assessments shall be performed at least annually to ensure that the organization addresses nonconformities of established policies, standards, procedures, and compliance obligations." Which of the following controls under the Audit Assurance and Compliance domain does this match to?
Options
- AAudit planning
- BInformation system and regulatory mapping
- CGDPR auditing
- DIndependent audits
How the community answered
(26 responses)- A8% (2)
- B73% (19)
- C15% (4)
- D4% (1)
Explanation
In the Cloud Control Matrix (CCM), the Audit Assurance and Compliance (AAC) domain's 'Information System and Regulatory Mapping' control addresses the requirement that organizations perform independent reviews and assessments at least annually to identify nonconformities with established policies, standards, procedures, and compliance obligations. This control ensures that information systems are mapped to applicable regulatory and policy requirements and that independent verification confirms conformance. Audit Planning (A) focuses on scoping and scheduling audits. Independent Audits (D) is a related but distinct control. GDPR Auditing (C) is not a CCM control category.
Topics
Community Discussion
No community discussion yet for this question.