CCAK · Question #56
Which of the following parties should have accountability for cloud compliance requirements?
The correct answer is B. Equally shared between customer and provider. Cloud compliance is governed by the shared responsibility model. Neither the customer nor the provider bears sole accountability. The cloud service provider is responsible for compliance related to the underlying infrastructure, physical security, and platform controls (e.g…
Question
Which of the following parties should have accountability for cloud compliance requirements?
Options
- ACustomer
- BEqually shared between customer and provider
- CProvider
- DEither customer or provider, depending on requirements
How the community answered
(28 responses)- B96% (27)
- D4% (1)
Explanation
Cloud compliance is governed by the shared responsibility model. Neither the customer nor the provider bears sole accountability. The cloud service provider is responsible for compliance related to the underlying infrastructure, physical security, and platform controls (e.g., hypervisor, network). The customer is responsible for compliance related to how they configure and use cloud services - including data governance, identity management, and application-level controls. Regulatory requirements (e.g., GDPR, HIPAA, PCI DSS) apply to both parties for their respective domains. Therefore, accountability is equally shared between customer and provider.
Topics
Community Discussion
No community discussion yet for this question.