Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CCAK Exam - Topic 3 Question 88 Discussion

A new company has all its operations in the cloud. Which of the following would be the BEST information security control framework to implement?
D) (S) Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM)
A) NIST 800-73, because it is a control framework implemented by the main cloud providers
B) ISO/IEC 27018
C) ISO/IEC 27002

Isaca CCAK Exam - Topic 3 Question 88 Discussion

Actual exam question for Isaca's CCAK exam
Question #: 88
Topic #: 3
[All CCAK Questions]

A new company has all its operations in the cloud. Which of the following would be the BEST information security control framework to implement?

Show Suggested Answer Hide Answer
Suggested Answer: D

The Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) would be the best information security control framework to implement for a new company that has all its operations in the cloud. The CCM is a cybersecurity control framework for cloud computing that is aligned to the CSA best practices and is considered the de-facto standard for cloud security and privacy. The CCM covers 17 domains and 197 control objectives that address all key aspects of cloud technology, such as data security, identity and access management, encryption and key management, incident response, audit assurance, and compliance. The CCM also maps to other industry-accepted security standards, regulations, and frameworks, such as ISO 27001/27002/27017/27018, NIST SP 800-53, PCI DSS, COBIT, FedRAMP, etc., which can help the company to achieve multiple compliance goals with one framework.The CCM also provides guidance on the shared responsibility model between cloud service providers and cloud customers, and helps to define the organizational relevance of each control12.


Cloud Controls Matrix (CCM) - CSA

Cloud Controls Matrix and CAIQ v4 | CSA - Cloud Security Alliance

Contribute your Thoughts:

0/2000 characters
Freeman
1 day ago
Surprised that people overlook ISO/IEC 27002, it's solid too!
upvoted 0 times
...
Lisandra
6 days ago
NIST 800-73 isn't really focused on cloud, though.
upvoted 0 times
...
Owen
11 days ago
Wait, isn't ISO/IEC 27018 also relevant for cloud privacy?
upvoted 0 times
...
Colette
17 days ago
Totally agree, CSA CCM is tailored for cloud environments!
upvoted 0 times
...
Karon
22 days ago
I think D is the best choice for cloud security.
upvoted 0 times
...
Tatum
27 days ago
I practiced a similar question where CSA CCM was highlighted as a strong framework for cloud environments, so I’m leaning towards that option.
upvoted 0 times
...
Ernest
1 month ago
I feel like NIST 800-73 is more about identity management, so it might not be the right fit for a cloud-only operation.
upvoted 0 times
...
Angella
1 month ago
I think ISO/IEC 27018 might be relevant since it focuses on protecting personal data in the cloud, but I need to double-check its applicability.
upvoted 0 times
...
Joye
1 month ago
I remember studying the CSA Cloud Controls Matrix, but I'm not sure if it's the best choice for a new company.
upvoted 0 times
...

Save Cancel