When mapping controls to architectural implementations, requirements define:
Requirements define control activities, which are the actions, processes, or mechanisms that are implemented to achieve the control objectives1.Control objectives are the targets or desired conditions to be met that are designed to ensure that policy intent is met2.Guidelines are the recommended practices or advice that provide flexibility in how to implement a policy, standard, or control3.Policies are the statements of management's intent that establish the direction, purpose, and scope of an organization's internal control system4.
COSO -- Control Activities - Deloitte1, section on Control Activities
Words Matter - Understanding Policies, Control Objectives, Standards ...2, section on Control Objectives
Understanding Policies, Control Objectives, Standards, Guidelines ...3, section on Guidelines
Internal Control Handbook4, section on Policies
A new company has all its operations in the cloud. Which of the following would be the BEST information security control framework to implement?
The Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) would be the best information security control framework to implement for a new company that has all its operations in the cloud. The CCM is a cybersecurity control framework for cloud computing that is aligned to the CSA best practices and is considered the de-facto standard for cloud security and privacy. The CCM covers 17 domains and 197 control objectives that address all key aspects of cloud technology, such as data security, identity and access management, encryption and key management, incident response, audit assurance, and compliance. The CCM also maps to other industry-accepted security standards, regulations, and frameworks, such as ISO 27001/27002/27017/27018, NIST SP 800-53, PCI DSS, COBIT, FedRAMP, etc., which can help the company to achieve multiple compliance goals with one framework.The CCM also provides guidance on the shared responsibility model between cloud service providers and cloud customers, and helps to define the organizational relevance of each control12.
Cloud Controls Matrix (CCM) - CSA
Cloud Controls Matrix and CAIQ v4 | CSA - Cloud Security Alliance
Which of the following is an example of financial business impact?
A DDoS attack renders the customer's cloud inaccessible for 24 hours, resulting in millions in lost sales is an example of financial business impact. Financial business impact refers to the extent of damage or harm that a threat can cause to the financial objectives and performance of the organization, such as revenue, profit, cash flow, or market share. A DDoS attack can cause a significant financial business impact by disrupting the normal operations and transactions of the organization, leading to loss of sales, customers, contracts, or opportunities. According to a report byKaspersky, the average cost of a DDoS attack for small and medium-sized businesses (SMBs) was $123,000 in 2019, while for enterprises it was $2.3 million.1Therefore, it is important for organizations to implement appropriate security measures and contingency plans to prevent or mitigate the effects of a DDoS attack.Reference:= The Future of Finance and the Global Economy: Facing Global ... - IMF2; Kaspersky: Cost of a DDoS Attack1
Which of the following is MOST important to ensure effective cloud application controls are maintained in an organization?
Exception reporting is crucial for maintaining effective cloud application controls within an organization. It involves monitoring and reporting deviations from standard operating procedures, which can indicate potential security issues. This proactive approach allows organizations to address vulnerabilities promptly before they can be exploited. Exception reporting is a key component of a robust security posture, as it provides real-time insights into the operational effectiveness of controls and helps maintain compliance with security policies.
Reference= The importance of exception reporting is highlighted in best practices for cloud security, which emphasize the need for continuous monitoring and immediate response to any anomalies detected in cloud applications
To promote the adoption of secure cloud services across the federal government by
The correct answer is A. To providing a standardized approach to security and risk assessment. This is the main purpose of FedRAMP, which is a government-wide program that promotes the adoption of secure cloud services across the federal government. FedRAMP provides a standardized methodology for assessing, authorizing, and monitoring the security of cloud products and services, and enables agencies to leverage the security assessments of cloud service providers (CSPs) that have been approved by FedRAMP.FedRAMP also establishes a baseline set of security controls for cloud computing, based on NIST SP 800-53, and provides guidance and templates for implementing and documenting the controls1.
The other options are incorrect because:
B . To provide agencies of the federal government a dedicated tool to certify Authority to Operate (ATO): FedRAMP does not provide a tool to certify ATO, but rather a process to obtain a provisional ATO (P-ATO) from the Joint Authorization Board (JAB) or an agency ATO from a federal agency.ATO is the official management decision given by a senior official to authorize operation of an information system and to explicitly accept the risk to agency operations, agency assets, or individuals based on the implementation of an agreed-upon set of security controls2.
C . To enable 3PAOs to perform independent security assessments of cloud service providers: FedRAMP does not enable 3PAOs to perform independent security assessments of CSPs, but rather requires CSPs to use 3PAOs for conducting independent security assessments as part of the FedRAMP process.3PAOs are independent entities that have been accredited by FedRAMP to perform initial and periodic security assessments of CSPs' systems and provide evidence of compliance with FedRAMP requirements3.
D . To publish a comprehensive and official framework for the secure implementation of controls for cloud security: FedRAMP does not publish a comprehensive and official framework for the secure implementation of controls for cloud security, but rather adopts and adapts the existing framework of NIST SP 800-53, which provides a catalog of security and privacy controls for federal information systems and organizations.FedRAMP tailors the NIST SP 800-53 controls to provide a subset of controls that are specific to cloud computing, and categorizes them into low, moderate, and high impact levels based on FIPS 1994.
Learn What FedRAMP is All About | FedRAMP | FedRAMP.gov
Guide for Applying the Risk Management Framework to Federal Information Systems - NIST
Third Party Assessment Organizations (3PAO) | FedRAMP.gov
Security and Privacy Controls for Federal Information Systems and Organizations - NIST
Sharon Thompson
7 days agoKenneth Martinez
21 days agoMark Rogers
1 month agoRonald Robinson
2 months agoEmma Davis
2 months agoSteven Carter
3 months agoJoshua Rivera
3 months agoJeffrey Mitchell
4 months agoBarbara Harris
4 months agoDonna King
5 months agoGary Johnson
5 months agoRobert Martinez
4 months agoCharles Turner
5 months agoGeorge Johnson
4 months agoEric White
5 months agoBasilia
6 months agoNan
6 months agoGeorgiana
6 months agoThad
6 months agoJani
6 months agoTamekia
7 months agoStephen
7 months agoLuisa
7 months agoLyda
8 months agoAnjelica
8 months agoVeronica
8 months agoAdelle
8 months agoDevorah
9 months agoCassie
9 months agoMargot
9 months agoMalika
9 months agoCarry
10 months agoBrice
10 months agoMatthew
10 months agoMargo
10 months agoSimona
11 months agoDona
11 months agoNaomi
11 months agoKallie
11 months agoCarlton
12 months agoTricia
12 months agoGarry
12 months agoMarnie
1 year agoMarnie
1 year agoFernanda
1 year agoDesire
1 year agoGlory
1 year agoJennifer
1 year agoCharlesetta
2 years agoFranchesca
2 years agoCory
2 years agoJanna
2 years agoIsadora
2 years agoMelina
2 years agoAlfreda
2 years agoDoug
2 years agoJacqueline
2 years agoAnjelica
2 years agoHelaine
2 years agoMaurine
2 years agoLatosha
2 years agoLazaro
2 years agoGeorgiana
2 years agoBrent
2 years agoCecily
2 years agoCheryl
2 years agoMyrtie
2 years agoViola
2 years agoCharlene
2 years agoColeen
2 years ago