nerdexam
(ISC)2

CCSP · Question #680

With the rapid emergence of cloud computing, very few regulations were in place that pertained to it specifically, and organizations often had to resort to using a collection of regulations that were

The correct answer is D. ISO/IEC 27018. ISO/IEC 27018 was implemented to address the protection of personal and sensitive information within a cloud environment. ISO/IEC 27001 and its later 27001:2015 revision are both general- purpose data security standards. ISO/IEC 19889 is an erroneous answer.

Submitted by katya_ua· Apr 18, 2026Legal, Risk and Compliance

Question

With the rapid emergence of cloud computing, very few regulations were in place that pertained to it specifically, and organizations often had to resort to using a collection of regulations that were not specific to cloud in order to drive audits and policies. Which standard from the ISO/IEC was designed specifically for cloud computing?

Options

  • AISO/IEC 27001
  • BISO/IEC 19889
  • CISO/IEC 27001:2015
  • DISO/IEC 27018

How the community answered

(18 responses)
  • B
    6% (1)
  • D
    94% (17)

Explanation

ISO/IEC 27018 was implemented to address the protection of personal and sensitive information within a cloud environment. ISO/IEC 27001 and its later 27001:2015 revision are both general- purpose data security standards. ISO/IEC 19889 is an erroneous answer.

Topics

#ISO/IEC Standards#Cloud Compliance#Data Protection#Cloud Regulations

Community Discussion

No community discussion yet for this question.

Full CCSP Practice