CCSK Legal, Compliance, and Audit in Cloud 1 — Questions and Answers
Question 1: What does CCSK identify as the primary legal challenge of cloud computing related to data location?
- Cloud providers charge more for data stored in regulated jurisdictions
- Data may reside in multiple jurisdictions simultaneously, creating complex and potentially conflicting legal obligations (Correct answer)
- Cloud data is exempt from national laws because it resides in a virtual environment
- Legal jurisdiction only applies to on-premises data storage
Correct answer: Data may reside in multiple jurisdictions simultaneously, creating complex and potentially conflicting legal obligations
Cloud data can be distributed across multiple countries, each with different privacy and security laws, creating jurisdictional conflicts and compliance complexity.
Question 2: What is a 'right to audit' clause in cloud contracts and why does CCSK consider it important?
- A clause allowing the cloud provider to audit customer usage for billing
- A contractual provision giving customers the right to audit or verify the provider's security controls (Correct answer)
- A regulatory requirement for annual financial audits of cloud services
- A clause that limits liability if a security audit fails
Correct answer: A contractual provision giving customers the right to audit or verify the provider's security controls
A right-to-audit clause ensures customers can verify provider security claims through audits or audit reports, maintaining accountability without relying solely on provider assertions.
Question 3: What is 'eDiscovery' in the context of CCSK and what cloud challenges does it present?
- A tool for discovering shadow IT cloud usage
- The legal process of identifying, collecting, and producing electronically stored information for legal proceedings, complicated in cloud by data distribution and provider access limits (Correct answer)
- A cloud provider's process for discovering security vulnerabilities
- A compliance framework for electronic health records in cloud
Correct answer: The legal process of identifying, collecting, and producing electronically stored information for legal proceedings, complicated in cloud by data distribution and provider access limits
Cloud eDiscovery is complicated because data may be distributed across jurisdictions, commingled with other tenants, and require provider assistance to collect.
Question 4: According to CCSK, what does 'compliance inheritance' mean for cloud customers?
- Customers automatically inherit all of the cloud provider's compliance certifications for their workloads
- Customers inherit compliance for the cloud infrastructure layer but remain responsible for compliance of their own applications and data (Correct answer)
- Compliance requirements are inherited from the customer's previous on-premises certifications
- Cloud providers inherit customer compliance obligations when data is migrated
Correct answer: Customers inherit compliance for the cloud infrastructure layer but remain responsible for compliance of their own applications and data
Compliance inheritance means customers benefit from provider certifications for the infrastructure layer but must achieve compliance for their own configuration, data, and applications.
Question 5: What is the purpose of a 'service level agreement' (SLA) from a security perspective in CCSK?
- SLAs only address performance metrics and have no security relevance
- SLAs define provider commitments for availability, security response times, and breach notification, creating contractual accountability (Correct answer)
- SLAs allow customers to waive security requirements
- SLAs are only relevant for SaaS services, not IaaS or PaaS
Correct answer: SLAs define provider commitments for availability, security response times, and breach notification, creating contractual accountability
SLAs include security commitments such as uptime guarantees, incident response timeframes, and breach notification obligations, providing contractual recourse if commitments fail.
Question 6: What does CCSK recommend organizations do when a cloud provider cannot provide sufficient audit evidence?
- Accept the provider's verbal assurances as sufficient
- Obtain third-party audit reports (SOC 2, ISO 27001) as a substitute for direct audit access (Correct answer)
- Terminate the cloud contract immediately
- Perform penetration testing on the provider's infrastructure
Correct answer: Obtain third-party audit reports (SOC 2, ISO 27001) as a substitute for direct audit access
When direct audit access is unavailable, third-party certification reports like SOC 2 Type II or ISO 27001 provide independent verification of provider security controls.
What does CCSK identify as the primary legal challenge of cloud computing related to data location?