nerdexam
(ISC)2

CISSP · Question #1148

As a design principle, which one of the following actors is responsible for identifying and approving data security requirements in a cloud ecosystem?

The correct answer is C. Cloud consumer. In a cloud ecosystem, the cloud consumer is the entity that owns the data and business requirements, making them responsible for identifying and approving data security requirements.

Submitted by manish99· Mar 5, 2026Security and Risk Management

Question

As a design principle, which one of the following actors is responsible for identifying and approving data security requirements in a cloud ecosystem?

Options

  • ACloud broker
  • BCloud provider
  • CCloud consumer
  • DCloud auditor

How the community answered

(18 responses)
  • C
    94% (17)
  • D
    6% (1)

Why each option

In a cloud ecosystem, the cloud consumer is the entity that owns the data and business requirements, making them responsible for identifying and approving data security requirements.

ACloud broker

The cloud broker acts as an intermediary that manages relationships between consumers and providers, but does not own the data and therefore does not have authority to identify or approve the consumer's data security requirements.

BCloud provider

The cloud provider is responsible for implementing and maintaining security controls within their infrastructure and services, but it is not their role to define or approve the data security requirements that belong to the consumer's business context.

CCloud consumerCorrect

The cloud consumer is the organization or individual that uses cloud services and owns the data being processed or stored. As the data owner, the cloud consumer is responsible for defining, identifying, and approving data security requirements to ensure their business and compliance needs are met, even when delegating implementation to other parties like the cloud provider.

DCloud auditor

The cloud auditor independently assesses and verifies security controls and compliance against established requirements, but their role is evaluative rather than prescriptive - they do not identify or approve the requirements themselves.

Concept tested: Cloud ecosystem roles and data security responsibility

Source: https://www.nist.gov/system/files/documents/itl/cloud/NIST_SP-500-292.pdf

Topics

#cloud security#shared responsibility model#data ownership#cloud consumer

Community Discussion

No community discussion yet for this question.

Full CISSP Practice