CCSP · Question #223
Which of the following are contractual components that the CSP should review and understand fully when contracting with a cloud service provider? (Choose two.)
The correct answer is B. Use of subcontractors D. Scope of processing. When contracting with a cloud service provider, the customer (CSP) must thoroughly understand the use of subcontractors and the explicit scope of processing to manage supply chain risks and ensure data privacy compliance.
Question
Which of the following are contractual components that the CSP should review and understand fully when contracting with a cloud service provider? (Choose two.)
Options
- AConcurrently maintainable site infrastructure
- BUse of subcontractors
- CRedundant site infrastructure capacity components
- DScope of processing
How the community answered
(69 responses)- A7% (5)
- B88% (61)
- C4% (3)
Why each option
When contracting with a cloud service provider, the customer (CSP) must thoroughly understand the use of subcontractors and the explicit scope of processing to manage supply chain risks and ensure data privacy compliance.
Concurrently maintainable site infrastructure is a technical design aspect that contributes to availability, but its specifics are typically a provider's internal concern, not an explicit contractual component a customer reviews in detail.
Understanding the use of subcontractors is critical as it identifies third parties who may access or process the customer's data, impacting security, compliance, and data sovereignty. This allows the customer to assess extended supply chain risks.
Redundant site infrastructure capacity components are technical details that ensure resilience; customers primarily focus on the service levels (SLAs) for availability, rather than the specific internal components achieving it.
Defining the scope of processing explicitly outlines what data the cloud provider is authorized to collect, store, process, and transmit, for what purposes, and under what conditions. This is fundamental for regulatory compliance, especially with data protection laws like GDPR, ensuring the provider does not exceed its contractual authority.
Concept tested: Cloud contract clauses for customers
Source: https://gdpr-info.eu/art-28-gdpr/
Topics
Community Discussion
No community discussion yet for this question.