Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil 312-40 Exam - Topic 2 Question 42 Discussion

The tech giant TSC uses cloud for its operations. As a cloud user, it should implement an effective risk management lifecycle to measure and monitor high and critical risks regularly. Additionally, TSC should define what exactly should be measured and the acceptable variance to ensure timely mitigated risks. In this case, which of the following can be used as a tool for cloud risk management?
D) CSA CCM Framework
A) Information System Audit and Control Association
B) Cloud Security Alliance
C) Committee of Sponsoring Organizations

Eccouncil 312-40 Exam - Topic 2 Question 42 Discussion

Actual exam question for Eccouncil's 312-40 exam
Question #: 42
Topic #: 2
[All 312-40 Questions]

The tech giant TSC uses cloud for its operations. As a cloud user, it should implement an effective risk management lifecycle to measure and monitor high and critical risks regularly. Additionally, TSC should define what exactly should be measured and the acceptable variance to ensure timely mitigated risks. In this case, which of the following can be used as a tool for cloud risk management?

Show Suggested Answer Hide Answer
Suggested Answer: D

The CSA CCM (Cloud Controls Matrix) Framework is a cybersecurity control framework for cloud computing, developed by the Cloud Security Alliance (CSA). It is designed to provide a structured and standardized set of security controls that help organizations assess the overall security posture of their cloud infrastructure and services.

Here's how the CSA CCM Framework serves as a tool for cloud risk management:

Comprehensive Controls: The CCM consists of 197 control objectives structured in 17 domains covering all key aspects of cloud technology.

Risk Assessment: It can be used for the systematic assessment of a cloud implementation, providing guidance on which security controls should be implemented.

Alignment with Standards: The controls framework is aligned with the CSA Security Guidance for Cloud Computing and other industry-accepted security standards and regulations.

Shared Responsibility Model: The CCM clarifies the shared responsibility model between cloud service providers (CSPs) and customers (CSCs).

Monitoring and Measurement: The CCM includes metrics and implementation guidelines that help define what should be measured and the acceptable variance for risks.


CSA's official documentation on the Cloud Controls Matrix (CCM), which outlines its use as a tool for cloud risk management1.

An article providing a checklist for CSA's Cloud Controls Matrix v4, which discusses how it can be used for managing risk in cloud environments2.

Contribute your Thoughts:

0/2000 characters
Laurene
5 hours ago
Definitely the Cloud Security Alliance!
upvoted 0 times
...
Emilio
5 days ago
I think the Information System Audit and Control Association might be more focused on traditional IT risks rather than cloud-specific ones.
upvoted 0 times
...
Temeka
11 days ago
I feel like I’ve seen questions about the Committee of Sponsoring Organizations before, but I’m not sure how it directly applies to cloud risk.
upvoted 0 times
...
Mose
16 days ago
I'm not entirely sure, but I think the Cloud Security Alliance has some good resources for managing risks in cloud environments.
upvoted 0 times
...
Yan
2 months ago
I remember studying the CSA CCM Framework; it seemed really relevant for cloud risk management.
upvoted 0 times
...

Save Cancel