CCAK · Question #5
An independent contractor is assessing security maturity of a SaaS company against industry standards. The SaaS company has developed and hosted all their products using the cloud services provided…
The correct answer is B. Review CSP's published questionnaires. CSPs like AWS, Azure, and GCP publish standardized security questionnaires - most notably the CSA STAR Consensus Assessments Initiative Questionnaire (CAIQ), which maps directly to the CCM. These published questionnaires provide a comprehensive, structured, and readily…
Question
An independent contractor is assessing security maturity of a SaaS company against industry standards. The SaaS company has developed and hosted all their products using the cloud services provided by a third-party cloud service provider (CSP). What is the optimal and most efficient mechanism to assess the controls CSP is responsible for?
Options
- AReview third-party audit reports.
- BReview CSP's published questionnaires.
- CDirectly audit the CSP.
- DSend supplier questionnaire to the CSP.
How the community answered
(36 responses)- A17% (6)
- B72% (26)
- C6% (2)
- D6% (2)
Explanation
CSPs like AWS, Azure, and GCP publish standardized security questionnaires - most notably the CSA STAR Consensus Assessments Initiative Questionnaire (CAIQ), which maps directly to the CCM. These published questionnaires provide a comprehensive, structured, and readily available self-disclosure of the CSP's security controls without requiring the auditor to negotiate access or wait for responses. Option A (third-party audit reports such as SOC 2 or ISO 27001 certificates) is useful but may be scoped narrowly and not cover all relevant controls. Option C (directly auditing the CSP) is impractical - major CSPs do not permit individual customer audits. Option D (sending a supplier questionnaire) duplicates what is already publicly available and is less efficient. The published questionnaire is the most efficient starting point.
Topics
Community Discussion
No community discussion yet for this question.