nerdexam
Isaca

CCAK · Question #5

An independent contractor is assessing security maturity of a SaaS company against industry standards. The SaaS company has developed and hosted all their products using the cloud services provided…

The correct answer is B. Review CSP's published questionnaires. CSPs like AWS, Azure, and GCP publish standardized security questionnaires - most notably the CSA STAR Consensus Assessments Initiative Questionnaire (CAIQ), which maps directly to the CCM. These published questionnaires provide a comprehensive, structured, and readily…

Cloud Auditing Basics and Tools

Question

An independent contractor is assessing security maturity of a SaaS company against industry standards. The SaaS company has developed and hosted all their products using the cloud services provided by a third-party cloud service provider (CSP). What is the optimal and most efficient mechanism to assess the controls CSP is responsible for?

Options

  • AReview third-party audit reports.
  • BReview CSP's published questionnaires.
  • CDirectly audit the CSP.
  • DSend supplier questionnaire to the CSP.

How the community answered

(36 responses)
  • A
    17% (6)
  • B
    72% (26)
  • C
    6% (2)
  • D
    6% (2)

Explanation

CSPs like AWS, Azure, and GCP publish standardized security questionnaires - most notably the CSA STAR Consensus Assessments Initiative Questionnaire (CAIQ), which maps directly to the CCM. These published questionnaires provide a comprehensive, structured, and readily available self-disclosure of the CSP's security controls without requiring the auditor to negotiate access or wait for responses. Option A (third-party audit reports such as SOC 2 or ISO 27001 certificates) is useful but may be scoped narrowly and not cover all relevant controls. Option C (directly auditing the CSP) is impractical - major CSPs do not permit individual customer audits. Option D (sending a supplier questionnaire) duplicates what is already publicly available and is less efficient. The published questionnaire is the most efficient starting point.

Topics

#CSP assessment#Vendor risk management#Cloud auditing mechanisms#Security controls assessment

Community Discussion

No community discussion yet for this question.

Full CCAK Practice