DOMAIN 2 - TOOLS OF CLOUD GOVERNANCE Flashcards

1
Q

The primary tool to extend governance into
business partners and providers.

A

Contracts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

performed by the potential cloud customer using available information and allowed processes/techniques. They combine
contractual and manual research with third-party attestations (legal statements often used
to communicate the results of an assessment or audit) and technical research. They are very
similar to any supplier assessment and can include aspects like financial viability, history,
feature offerings, third-party attestations, feedback from peers, and so on.

A

Supplier (cloud provider) Assessments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

includes all the documentation on a provider’s internal (i.e. self) and external compliance assessments. They are the reports from audits of controls, which an organization can perform themselves, a customer can perform on a provider (although this usually isn’t an option in cloud), or have performed by a trusted third
party. Third-party audits and assessments are preferred since they provide independent validation (assuming you trust the third party).

A

Compliance reporting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Standards like the _________ have a defined
scope, which includes both what is assessed (e.g. which of the provider’s services) as well as which controls are assessed.

A

SSAE 16

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

an assurance program and documentation registry for cloud provider assessments based on the CSA Cloud Controls Matrix and Consensus

A

CLOUD SECURITY ALLIANCE STAR REGISTRY

How well did you know this?
1
Not at all
2
3
4
5
Perfectly