CCSP: Domain 5 - Vendor Management Flashcards
What are the steps in the vendor management lifecycle? (4)
- vendor selection
- onboarding
- maintenance
- offboarding
What are the common clauses and sections found in cloud service agreements? (8)
- definition of terms
- performance metrics and remedies
- data ownership
- compliance obligations
- assurance
- indemnification
- termination
- litigation
Why does a contract need definition of terms?
it has to be clear what do the used terms mean; e.g. what exactly is meant by outage?
What are Service Level Management practices?
cloud customer monitoring vendor’s compliance with SLAs
What should a contract specify, when it comes to data ownership?
customer retains any data that it uses in the cloud service
What do cloud vendor compliance obligations entail in a contract?
the contract needs to include all the compliance regulations and laws that the cloud customer is subject to and therefore cloud provider needs to be too
What does assurance entail in cloud contracts?
ability to implement assurance measures that allow to verify, that the vendor is living up to its obligations under the contract
What does litigation need to cover in contracts?
the jurisdiction of the litigation
What does scoping mean in the context of engaging and selecting cloud vendor?
term used for only including departments or units impacted by the cloud engagement
When choosing a CSP, it is important to evaluate several factors to understand the risk. What are the questions that need to be asked?
- Is the provider subject to takeover or acquisition?
- How financially stable is the provider?
- In what legal jurisdictions are the provider’s offices located?
- Are there outstanding lawsuits against the provider?
- What pricing protections are in place for services contracted?
- How will a provider satisfy any regulatory or legal compliance requiremetns?
- What does failover, backup and recovery look like for a provider?
What framework is provided by CSA to evaluate risk in CSPs?
CSA STAR (Security, Trust, Assurance, Risk)
What does the CSA STAR (Security, Trust, Assurance, Risk) contain?
evaluations of cloud services against the CSA’s cloud control matrix (CCM)
What kind of assessments can be used with CSA STAR (Security, Trust, Assurance, Risk)?
self-assessment or third-party assessment; affects the level of assurance (self - low, 3rd party - high)
What wieght does the CSA STAR (Security, Trust, Assurance, Risk) have?
lightweight, lower assurance cetification for the CSPs that use it
What is island hopping attack?
attack on an organization through a compromised vendor