Domain 4 - Compliance and Audit Management Flashcards

1
Q

How does cloud computing affect compliance and audit?

A
  1. Cross border jurisdictional issues
  2. Division of responsibility between provider and customer
  3. Inheriting compliance controls from CSPs
  4. How evidence is provided
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What’s the difference between compliance and audits?

A
  • Compliance validates awareness of and adhere to corporate obligations (Corporate Social Responsibility, Laws, Regs, Contracts, Ethics, contracts, strategies and policies. etc.)
  • Audits are a key tool for providing compliance.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Compliance Management?

A
  • A tool of governance
  • How organization assesses, remediates, and proves it is meeting internal and external obligations.
  • Many regulations and obligations require a certain level of security.
  • This is why compliance is so closely tied to security.
  • Security controls are an important tool to assure compliance.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What’s the impact of cloud on compliance?

A
  • Compliance is a shared responsibility; customer is ultimately responsible for your own compliance.
  • Reliance on 3P Audits
  • National/International jurisdiction - e.g. a developer can easily deploy service in a different Region without having to get the necessary approvals.
  • Not all CSP services may be in scope of compliance.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are audits and assessments?

A
  • Mechanisms to document compliance with internal and external requirements.
  • Reporting includes compliance determination, identified issues, risks and remediation recommendations.
  • Audits have scope and statement of applicability
  • SoA says what is being evaluated (e.g. all systems with financial data)
  • Information Security Audits typically focus on effectiveness of security management and controls.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly