ExamGecko
Question list
Search
Search

List of questions

Search

Question 160 - CCAK discussion

Report
Export

In a situation where duties related to cloud risk management and control are split between an organization and its cloud service providers, which of the following would BEST help to ensure a coordinated approach to risk and control processes?

A.

Establishing a joint security operations center

Answers
A.

Establishing a joint security operations center

B.

Automating reporting of risk and control compliance

Answers
B.

Automating reporting of risk and control compliance

C.

Co-locating compliance management specialists

Answers
C.

Co-locating compliance management specialists

D.

Maintaining a centralized risk and controls dashboard

Answers
D.

Maintaining a centralized risk and controls dashboard

Suggested answer: D

Explanation:

A centralized risk and controls dashboard is the best option for ensuring a coordinated approach to risk and control processes when duties are split between an organization and its cloud service providers. This dashboard provides a unified view of risk and control status across the organization and the cloud services it utilizes. It enables both parties to monitor and manage risks effectively and ensures that control activities are aligned and consistent. This approach supports proactive risk management and facilitates communication and collaboration between the organization and the cloud service provider.

Reference The concept of a centralized risk and controls dashboard is supported by the Cloud Security Alliance (CSA) and ISACA, which emphasize the importance of visibility and coordination in cloud risk management.The CCAK materials and the Cloud Controls Matrix (CCM) provide guidance on establishing such dashboards as a means to manage and mitigate risks in a cloud environment12.

asked 17/11/2024
Hector Moreno
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first