DOMAIN 2 - CLOUD RISK MANAGEMENT TRADE-OFFs AND TOOLS Flashcards
There is less physical control over _______ and their controls and processes. You don’t physically control the infrastructure or the provider’s internal processes.
assets
There is a greater reliance on ________, audits, and assessments, as you lack day-to-day visibility or management.
contracts
This creates an increased requirement for proactive management of relationship and adherence to contracts, which extends beyond the initial contract signing and audits. Cloud providers also constantly evolve their products and services to remain competitive and these ongoing innovations might
exceed, strain, or not be covered by existing ___________.
agreements and assessments.
Cloud customers have a reduced need (and associated reduction in costs) to manage risks that the cloud provider accepts under the _________. You haven’t outsourced accountability for managing the risk, but you can certainly outsource the
management of some risks.
shared responsibility model
The __________ sets the groundwork for the cloud risk management program:
supplier assessment
After reviewing and understanding what risks the cloud provider manages, what remains is ________.
residual risk
_________, most often enabled by insurance, is an imperfect mechanism, especially for information risks
Risk transfer