nerdexam
CSA

CCSK · Question #178

If a provider's infrastructure is not in scope, who is responsible for building compliant applications and services?

The correct answer is A. The customer is responsible for compliant applications and services. When a cloud provider's infrastructure is outside compliance scope, the shared responsibility model places full accountability for compliant application and service design on the customer.

Legal, Risk, and Compliance

Question

If a provider's infrastructure is not in scope, who is responsible for building compliant applications and services?

Options

  • AThe customer is responsible for compliant applications and services.
  • BIt is up to the customer and provider to negotiate the solution.
  • CThe provider must update or fix whatever is not in compliance.
  • DNo one. It is an accepted risk that is written into the terms and conditions with customers.
  • EThe provider must create a separate tenant for each customer based on the various compliance

How the community answered

(57 responses)
  • A
    75% (43)
  • B
    2% (1)
  • C
    7% (4)
  • D
    14% (8)
  • E
    2% (1)

Why each option

When a cloud provider's infrastructure is outside compliance scope, the shared responsibility model places full accountability for compliant application and service design on the customer.

AThe customer is responsible for compliant applications and services.Correct

The cloud shared responsibility model dictates that compliance obligations are divided based on what each party controls. When the provider's underlying infrastructure is not in scope for a given compliance framework, the customer must independently design, implement, and operate their applications and services to satisfy those requirements. The customer cannot rely on the provider to fulfill compliance obligations that fall outside the agreed-upon scope.

BIt is up to the customer and provider to negotiate the solution.

Scope boundaries are established during contract negotiation; once infrastructure is defined as out of scope, ongoing negotiation does not shift or share the customer's resulting compliance burden.

CThe provider must update or fix whatever is not in compliance.

If the provider's infrastructure is not in compliance scope, the provider has no contractual or regulatory obligation to remediate compliance gaps on the customer's behalf.

DNo one. It is an accepted risk that is written into the terms and conditions with customers.

Compliance requirements cannot simply be accepted as risk and buried in terms and conditions; customers remain legally and contractually accountable for meeting applicable standards.

EThe provider must create a separate tenant for each customer based on the various compliance

Provisioning separate tenants per customer is a multi-tenancy architecture decision, not a mechanism that transfers or satisfies the customer's responsibility to build compliant applications.

Concept tested: Cloud shared responsibility model and compliance scope

Source: https://cloudsecurityalliance.org/research/guidance/

Topics

#compliance responsibility#customer obligations#provider scope#cloud compliance

Community Discussion

No community discussion yet for this question.

Full CCSK Practice