CISM · Question #629
An information security manager is assessing security risk associated with a cloud service provider. Which of the following is the MOST appropriate reference to consult when performing this…
The correct answer is D. Security control frameworks. Security control frameworks (D) - such as ISO/IEC 27001, SOC 2 Type II, NIST CSF, or the CSA Cloud Controls Matrix (CCM) - provide comprehensive, standardized, and vendor-neutral criteria for evaluating whether a cloud provider has adequate controls in place. They enable…
Question
An information security manager is assessing security risk associated with a cloud service provider. Which of the following is the MOST appropriate reference to consult when performing this assessment?
Options
- APrevious provider service level agreements (SLAs)
- BPenetration test results from the provider
- CThreat intelligence reports
- DSecurity control frameworks
How the community answered
(34 responses)- A9% (3)
- B18% (6)
- C3% (1)
- D71% (24)
Explanation
Security control frameworks (D) - such as ISO/IEC 27001, SOC 2 Type II, NIST CSF, or the CSA Cloud Controls Matrix (CCM) - provide comprehensive, standardized, and vendor-neutral criteria for evaluating whether a cloud provider has adequate controls in place. They enable consistent, repeatable assessments against industry-accepted benchmarks. Previous SLAs (A) address service availability commitments, not security control adequacy. Penetration test results (B) are point-in-time assessments of specific attack vectors and not a holistic view of the provider's control environment. Threat intelligence reports (C) inform the threat landscape but do not evaluate the provider's internal controls. Frameworks are the authoritative reference for a structured risk assessment.
Topics
Community Discussion
No community discussion yet for this question.