Question 86

During an audit, it was identified that a critical application hosted in an off-premises cloud is not part of the organization's disaster recovery plan (DRP). Management stated that it is responsible for ensuring the cloud service provider has a plan that is tested annually. What should be the auditor's NEXT course of action?
  • Question 87

    Which of the following types of risk is associated specifically with the use of multi-cloud environments in an organization?
  • Question 88

    Which of the following is MOST useful for an auditor to review when seeking visibility into the cloud supply chain for a newly acquired Software as a Service (SaaS) solution?
  • Question 89

    Due to cloud audit team resource constraints, an audit plan as initially approved cannot be completed. Assuming that the situation is communicated in the cloud audit report which course of action is MOST relevant?
  • Question 90

    An auditor is assessing a European organization's compliance. Which regulation is suitable if health information needs to be protected?