CCSK · Question #204
How can a multi-tenant data center provider readily meet the audit requirements of most customers?
The correct answer is E. Audit against a regulatory and security standard template and publish the results to the customers. Multi-tenant providers can efficiently satisfy diverse customer audit needs by auditing against recognized standards and publishing results, avoiding the impracticality of granting direct access to each customer.
Question
How can a multi-tenant data center provider readily meet the audit requirements of most customers?
Options
- AAllow unlimited data auditing by any party, especially governments
- BDesignate your data center for non-regulated information only, so that no audits will be required
- CAllow self-auditing by each customer so that they can meet their own requirements
- DAuditing is not required when data is stored at a third party data center
- EAudit against a regulatory and security standard template and publish the results to the customers
How the community answered
(67 responses)- A10% (7)
- B1% (1)
- C4% (3)
- D1% (1)
- E82% (55)
Why each option
Multi-tenant providers can efficiently satisfy diverse customer audit needs by auditing against recognized standards and publishing results, avoiding the impracticality of granting direct access to each customer.
Allowing unlimited auditing by any party, including governments, is operationally infeasible in a multi-tenant environment and creates security and confidentiality risks for all tenants.
Restricting a data center to non-regulated data only is not a viable business strategy and does not eliminate compliance obligations, as many data types carry regulatory requirements regardless of where they are stored.
Self-auditing by customers lacks the independence and objectivity required by most regulatory frameworks such as SOC 2, ISO 27001, and PCI DSS, making it insufficient for formal compliance.
Storing data at a third party does not transfer or eliminate audit obligations; compliance requirements follow the data and apply to both the customer and the provider handling it.
Auditing against established frameworks such as ISO 27001, SOC 2 Type II, or PCI DSS and sharing the resulting reports allows a single audit to satisfy the requirements of many customers simultaneously. This approach provides the independent verification customers and regulators require while protecting the security and confidentiality of a shared infrastructure that cannot be opened to unlimited individual audits.
Concept tested: Multi-tenant cloud provider audit compliance strategy
Source: https://cloudsecurityalliance.org/research/guidance/
Topics
Community Discussion
No community discussion yet for this question.