nerdexam
Isaca

CCAK · Question #84

The BEST method to report continuous assessment of a cloud provider's services to the CSA is through:

The correct answer is C. CCM assessment by a third-party auditor on a periodic basis. The Cloud Security Alliance (CSA) accepts and endorses Cloud Controls Matrix (CCM) assessments conducted by qualified third-party auditors as the standard mechanism for cloud providers to report their security posture to the CSA STAR (Security, Trust, Assurance, and Risk)…

Cloud Audit Reporting and Assurance

Question

The BEST method to report continuous assessment of a cloud provider's services to the CSA is through:

Options

  • Aa set of dedicated application programming interfaces (APIs).
  • BSOC 2 Type 2 attestation.
  • CCCM assessment by a third-party auditor on a periodic basis.
  • Dtools selected by the third-party auditor.

How the community answered

(17 responses)
  • B
    12% (2)
  • C
    82% (14)
  • D
    6% (1)

Explanation

The Cloud Security Alliance (CSA) accepts and endorses Cloud Controls Matrix (CCM) assessments conducted by qualified third-party auditors as the standard mechanism for cloud providers to report their security posture to the CSA STAR (Security, Trust, Assurance, and Risk) registry. This is the most recognized and structured path for continuous or periodic assessment reporting to CSA. While APIs (A) can enable automated data exchange, they are not the primary reporting mechanism CSA specifies. SOC 2 Type 2 (B) is a separate attestation standard not directly submitted to CSA. Tools selected by auditors (D) is too vague and not a defined reporting standard.

Topics

#Cloud Controls Matrix (CCM)#CSA STAR#Third-party assurance#Continuous assessment

Community Discussion

No community discussion yet for this question.

Full CCAK Practice