CGEIT · Question #477
When selecting a cloud provider, which of the following provides the MOST comprehensive information regarding the current status and effectiveness of the provider's controls?
The correct answer is B. Third-party audit report. When selecting a cloud provider, a third-party audit report offers the most comprehensive information on the current status and effectiveness of the provider's controls.
Question
When selecting a cloud provider, which of the following provides the MOST comprehensive information regarding the current status and effectiveness of the provider's controls?
Options
- AGlobally recognized certification
- BThird-party audit report
- CControl self-assessment (CSA)
- DMaturity assessment
How the community answered
(36 responses)- A8% (3)
- B72% (26)
- C3% (1)
- D17% (6)
Why each option
When selecting a cloud provider, a third-party audit report offers the most comprehensive information on the current status and effectiveness of the provider's controls.
A globally recognized certification indicates compliance with a standard but does not provide the granular, detailed information on control implementation and effectiveness found in the full audit report.
Third-party audit reports, such as SOC 2 or ISO 27001 audit reports, provide an independent and objective evaluation by external auditors of the design and operational effectiveness of a cloud provider's security and other relevant controls, offering detailed assurance.
A Control Self-Assessment (CSA) is an internal review by the provider, which lacks the objectivity and independent validation of an external third-party audit.
A maturity assessment evaluates the sophistication of processes over time but does not offer specific, point-in-time evidence of the effectiveness of individual controls.
Concept tested: Cloud provider due diligence, third-party assurance reports
Source: https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2
Topics
Community Discussion
No community discussion yet for this question.