Question 161

Who should define what constitutes a policy violation?
  • Question 162

    Which of the following is a cloud-specific security standard?
  • Question 163

    A cloud service customer is looking to subscribe to a finance solution provided by a cloud service provider.
    The provider has clarified that the audit logs cannot be taken out of the cloud environment by the customer to its security information and event management (SIEM) solution for monitoring purposes. Which of the following should be the GREATEST concern to the auditor?
  • Question 164

    Which of the following should be an assurance requirement when an organization is migrating to a Software as a Service (SaaS) provider?
  • Question 165

    When establishing cloud governance, an organization should FIRST test by migrating: