CCSK · Question #22
Which of the following statements are NOT requirements of governance and enterprise risk management in a cloud environment?
The correct answer is E. Both B and C. This question identifies which statements do NOT qualify as requirements of governance and enterprise risk management in a cloud environment. The correct answer pairs two statements that fall outside recognized ERM obligations.
Question
Which of the following statements are NOT requirements of governance and enterprise risk management in a cloud environment?
Options
- AInspect and account for risks inherited from other members of the cloud supply chain and take
- BRespect the interdependency of the risks inherent in the cloud supply chain and communicate the
- CNegotiate long-term contracts with companies who use well-vetted software application to avoid
- DProvide transparency to stakeholders and shareholders demonstrating fiscal solvency and
- EBoth B and C.
How the community answered
(33 responses)- A3% (1)
- B3% (1)
- D9% (3)
- E85% (28)
Why each option
This question identifies which statements do NOT qualify as requirements of governance and enterprise risk management in a cloud environment. The correct answer pairs two statements that fall outside recognized ERM obligations.
Inspecting and accounting for risks inherited from cloud supply chain members is a core, formally recognized requirement of cloud governance and enterprise risk management.
Although B appears to describe a legitimate activity, it is identified as a non-requirement in this context - selecting only B ignores that C is equally not a requirement, making E the complete answer.
Negotiating long-term contracts with vetted software vendors is a procurement consideration, not an ERM governance requirement - but selecting only C misses that B is also designated a non-requirement.
Providing transparency to stakeholders and shareholders is a recognized and legitimate cloud governance obligation, making it a genuine requirement rather than an exception.
Negotiating long-term contracts based on software vetting (C) is a procurement strategy, not a defined governance or ERM requirement in cloud environments. The framing in B, which describes respecting supply chain risk interdependency and communicating it, does not match any formally recognized ERM requirement - recognized obligations focus on assessing and accounting for inherited risks and providing stakeholder transparency, as reflected in A and D.
Concept tested: Cloud governance and enterprise risk management requirements
Source: https://cloudsecurityalliance.org/research/guidance/
Topics
Community Discussion
No community discussion yet for this question.