Legal, Compliance, and Audit in Cloud Flashcards
6 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Legal, Compliance, and Audit in Cloud flashcards as text
What does the GDPR require of cloud customers regarding data processing by cloud providers?
Answer: Customers must enter into Data Processing Agreements (DPAs) with cloud providers who process EU personal data on their behalf
GDPR requires data controllers (customers) to have DPAs with processors (cloud providers) ensuring the provider handles EU personal data per GDPR requirements.
What is a 'SOC 2 Type II' report and why is it relevant to CCSK cloud security assessments?
Answer: An independent auditor's report verifying a cloud provider's security controls operated effectively over a defined period (typically 12 months)
SOC 2 Type II covers operational effectiveness of controls over time (vs. Type I which is point-in-time), providing stronger assurance of consistent security practices.
According to CCSK, what is 'regulatory arbitrage' in cloud computing and why is it a concern?
Answer: Storing data in jurisdictions with weaker privacy laws to avoid stricter regulations, undermining compliance intent
Regulatory arbitrage exploits jurisdictional differences by storing data where regulations are weakest, which may violate the intent of regulations in the customer's home jurisdiction.
What is 'ISO/IEC 27017' and how does it differ from ISO/IEC 27001 in cloud security?
Answer: ISO 27017 provides cloud-specific security controls extending ISO 27001, addressing cloud-unique risks like virtual environments and shared infrastructure
ISO 27017 extends the ISO 27001 framework with additional controls specific to cloud services, covering topics like virtual machines, provider-customer responsibilities, and asset ownership.
What does CCSK say about the handling of 'personally identifiable information' (PII) in cloud audit logs?
Answer: Audit logs containing PII must be protected with the same controls as other sensitive data, and retention periods must comply with privacy regulations
Audit logs often contain PII (usernames, IP addresses, access details) and must be protected, access-controlled, and retained per applicable privacy and compliance requirements.
According to CCSK, what is 'contractual security requirements' in cloud vendor management?
Answer: Explicit security obligations written into cloud contracts covering data protection, breach notification, audit rights, and compliance
Contractual security requirements formalize provider security obligations, ensuring accountability for data protection, incident notification, and compliance support.