CCSP: Domain 6 - Contracts Flashcards

1
Q

Organization wants to ensure, that it will not be held accountable if something goes wrong that their PaaS provider is responsible for. What should they require in the cloud contract?

A

indemnification

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Can legal liability be transferred to the cloud provider?

A

no

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is MSA?

A
  • Master Services Agreement
  • document that describes how two organizations intend to work together over time; work is then described in statements of work (SOWs)
  • umbrella document that governs many different projects conducted by the same service provider
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is SOW?

A
  • Statement of Work
  • governs a specific unit of work
  • description of a project within Master Services Agreement
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What should MSA address?

A

compliance and process requirements the customer is passing along to CSP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What should MSA include?

A

breach notification; CSP duty to inform the customer of a breach within a specific time period after detection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Is SLA legally binding?

A

yes; often includes financial penalties for non-performance, and may allow customer to terminate a contract

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a Service Level Requirement (SLR)?

A

document that captures the specific requirements and expectations of the customer(s) before the service is designed or implemented; serves as input for the service design process

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the common elements documented in an SLA?

A
  • uptime guarantees
  • SLA violation penalties
  • SLA violation penalty exclusions and limitations
  • suspension of service clauses
  • provider liability
  • data protection and management
  • disaster recovery and recovery point objectives
  • security and privacy notifications and timeframes
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

When is Statement of Work created?

A

after MSA has been executed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Is SOW a legal document?

A

yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does MSA typically document?

A

services and prices; focus os “overall, ongoing”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does SOW typically cover?

A

requirements, expectations and deliverables for a project “limited & specific”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

When is insurance broker useful?

A
  • when investigating insurance options for organization’s circumstances, including:
    • the amount of coverage needed
    • different types of coverage, such as business interruption or cyber extortion
    • security controls that the insurance require, such as MFA
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

When does cyber risk usually cover costs?

A
  • investigation
  • direct business losses
  • recovery costs
  • legal notifications
  • lawsuits
  • extortion
  • food and related expenses
How well did you know this?
1
Not at all
2
3
4
5
Perfectly