Which of the following is an example of a corrective control?
Which of the following is a cloud-specific security standard?
Regarding suppliers of a cloud service provider, it is MOST important for the auditor to be aware that the:
DevSecOps aims to integrate security tools and processes directly into the software development life cycle and should be done:
In a multi-level supply chain structure where cloud service provider A relies on other sub cloud services, the provider should ensure that any compliance requirements relevant to the provider are:
Which of the following methods can be used by a cloud service provider with a cloud customer that does not want to share security and control information?
"Policies and procedures shall be established, and supporting business processes and technical measures implemented, for maintenance of several items ensuring continuity and availability of operations and support personnel." Which of the following types of controls BEST matches this control description?
Which of the following BEST describes the difference between a Type 1 and a Type 2 SOC report?
To BEST prevent a data breach from happening, cryptographic keys should be:
In a multi-level supply chain structure where cloud service provider A relies on other sub cloud services, the provider should ensure that any compliance requirements relevant to the provider are: