Line of Defense Flashcards
1st Line: Operational Management
Business Units, IT, and Ops Teams “- Implement and manage controls.
- Identify and manage risks in daily operations.” “- Secure cloud configurations (e.g., storage, VMs).
- Manage user access.
- Monitor cloud resources.”
2nd Line: Risk Management & Compliance
Risk Managers, Compliance Officers, Security Teams “- Oversee operational teams.
- Develop policies, standards, and guidelines.
- Monitor compliance.” “- Use frameworks like ISO/IEC 27001.
- Assess cloud provider risks.
- Ensure GDPR or HIPAA compliance.”
3rd Line: Internal and External Audit
Internal Audit Teams, External Auditors “- Provide independent assurance.
- Evaluate controls and risk management.
- Report to leadership.” “- Conduct cloud audits (e.g., SOC 2, FedRAMP).
- Test data protection controls.
- Report findings.”