Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil 312-40 Exam - Topic 2 Question 42 Discussion

The tech giant TSC uses cloud for its operations. As a cloud user, it should implement an effective risk management lifecycle to measure and monitor high and critical risks regularly. Additionally, TSC should define what exactly should be measured and the acceptable variance to ensure timely mitigated risks. In this case, which of the following can be used as a tool for cloud risk management?
D) CSA CCM Framework
A) Information System Audit and Control Association
B) Cloud Security Alliance
C) Committee of Sponsoring Organizations

Eccouncil 312-40 Exam - Topic 2 Question 42 Discussion

Actual exam question for Eccouncil's 312-40 exam
Question #: 42
Topic #: 2
[All 312-40 Questions]

The tech giant TSC uses cloud for its operations. As a cloud user, it should implement an effective risk management lifecycle to measure and monitor high and critical risks regularly. Additionally, TSC should define what exactly should be measured and the acceptable variance to ensure timely mitigated risks. In this case, which of the following can be used as a tool for cloud risk management?

Show Suggested Answer Hide Answer
Suggested Answer: D

The CSA CCM (Cloud Controls Matrix) Framework is a cybersecurity control framework for cloud computing, developed by the Cloud Security Alliance (CSA). It is designed to provide a structured and standardized set of security controls that help organizations assess the overall security posture of their cloud infrastructure and services.

Here's how the CSA CCM Framework serves as a tool for cloud risk management:

Comprehensive Controls: The CCM consists of 197 control objectives structured in 17 domains covering all key aspects of cloud technology.

Risk Assessment: It can be used for the systematic assessment of a cloud implementation, providing guidance on which security controls should be implemented.

Alignment with Standards: The controls framework is aligned with the CSA Security Guidance for Cloud Computing and other industry-accepted security standards and regulations.

Shared Responsibility Model: The CCM clarifies the shared responsibility model between cloud service providers (CSPs) and customers (CSCs).

Monitoring and Measurement: The CCM includes metrics and implementation guidelines that help define what should be measured and the acceptable variance for risks.


CSA's official documentation on the Cloud Controls Matrix (CCM), which outlines its use as a tool for cloud risk management1.

An article providing a checklist for CSA's Cloud Controls Matrix v4, which discusses how it can be used for managing risk in cloud environments2.

Contribute your Thoughts:

0/2000 characters
Gearldine
2 days ago
Wow, I didn’t know there were so many tools for cloud risk management!
upvoted 0 times
...
Leonida
7 days ago
For sure, the Information System Audit and Control Association is a solid option too.
upvoted 0 times
...
Francis
12 days ago
Wait, I thought the Committee of Sponsoring Organizations was more relevant?
upvoted 0 times
...
Marg
18 days ago
I think the CSA CCM Framework is the best choice here.
upvoted 0 times
...
Janae
23 days ago
Definitely the Cloud Security Alliance!
upvoted 0 times
...
Quinn
28 days ago
Not convinced that any of these will really help TSC.
upvoted 0 times
...
Merissa
1 month ago
A) is a solid option too, but not as focused on cloud.
upvoted 0 times
...
Fannie
1 month ago
Wait, are we sure TSC even needs all this?
upvoted 0 times
...
Odette
1 month ago
I think the CSA CCM Framework is the best choice.
upvoted 0 times
...
Laurene
2 months ago
Definitely the Cloud Security Alliance!
upvoted 0 times
...
Emilio
2 months ago
I think the Information System Audit and Control Association might be more focused on traditional IT risks rather than cloud-specific ones.
upvoted 0 times
...
Temeka
2 months ago
I feel like I’ve seen questions about the Committee of Sponsoring Organizations before, but I’m not sure how it directly applies to cloud risk.
upvoted 0 times
...
Mose
2 months ago
I'm not entirely sure, but I think the Cloud Security Alliance has some good resources for managing risks in cloud environments.
upvoted 0 times
...
Yan
4 months ago
I remember studying the CSA CCM Framework; it seemed really relevant for cloud risk management.
upvoted 0 times
...

Save Cancel