Question 61

Which of the following is the FIRST step of the Cloud Risk Evaluation Framework?
  • Question 62

    Which of the following key stakeholders should be identified FIRST when an organization is designing a cloud compliance program?
  • Question 63

    Which of the following methods can be used by a cloud service provider with a cloud customer that does not want to share security and control information?
  • Question 64

    Which of the following is the PRIMARY area for an auditor to examine in order to understand the criticality of the cloud services in an organization, along with their dependencies and risks?
  • Question 65

    Which of the following attestations allows for immediate adoption of the Cloud Controls Matrix (CCM) as additional criteria to AICPA Trust Service Criteria and provides the flexibility to update the criteria as technology and market requirements change?