โ† All CCSK Flashcard Decks

Legal, Compliance, and Audit in Cloud Flashcards

6 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Legal, Compliance, and Audit in Cloud flashcards as text
  1. What does CCSK identify as the primary legal challenge of cloud computing related to data location?

    Answer: Data may reside in multiple jurisdictions simultaneously, creating complex and potentially conflicting legal obligations

    Cloud data can be distributed across multiple countries, each with different privacy and security laws, creating jurisdictional conflicts and compliance complexity.

  2. What is a 'right to audit' clause in cloud contracts and why does CCSK consider it important?

    Answer: A contractual provision giving customers the right to audit or verify the provider's security controls

    A right-to-audit clause ensures customers can verify provider security claims through audits or audit reports, maintaining accountability without relying solely on provider assertions.

  3. What is 'eDiscovery' in the context of CCSK and what cloud challenges does it present?

    Answer: The legal process of identifying, collecting, and producing electronically stored information for legal proceedings, complicated in cloud by data distribution and provider access limits

    Cloud eDiscovery is complicated because data may be distributed across jurisdictions, commingled with other tenants, and require provider assistance to collect.

  4. According to CCSK, what does 'compliance inheritance' mean for cloud customers?

    Answer: Customers inherit compliance for the cloud infrastructure layer but remain responsible for compliance of their own applications and data

    Compliance inheritance means customers benefit from provider certifications for the infrastructure layer but must achieve compliance for their own configuration, data, and applications.

  5. What is the purpose of a 'service level agreement' (SLA) from a security perspective in CCSK?

    Answer: SLAs define provider commitments for availability, security response times, and breach notification, creating contractual accountability

    SLAs include security commitments such as uptime guarantees, incident response timeframes, and breach notification obligations, providing contractual recourse if commitments fail.

  6. What does CCSK recommend organizations do when a cloud provider cannot provide sufficient audit evidence?

    Answer: Obtain third-party audit reports (SOC 2, ISO 27001) as a substitute for direct audit access

    When direct audit access is unavailable, third-party certification reports like SOC 2 Type II or ISO 27001 provide independent verification of provider security controls.