C. Audit the effectiveness of the cloud provider’s supplier management program.
When auditing a cloud service provider, it's important to ensure that the provider's suppliers (often referred to as "subservice organizations") are also effectively managed and compliant with relevant standards and requirements. By auditing the effectiveness of the cloud provider's supplier management program, the auditor can assess how well the cloud provider manages its relationships with suppliers, including how it ensures that those suppliers meet necessary compliance and security standards. This approach allows the auditor to evaluate the risks associated with the supply chain without needing to directly audit each individual supplier.
P# 63 If the CSP outsources parts of its infrastructure, operations or maintenance, these third parties may not satisfy or support the requirements that the CSP is contracted to provide to cloud customers. An organization needs to evaluate how the CSP enforces compliance and check if the CSP flows its own requirements down to third parties. Having regular discussions with the CSPs on supply chain contractual requirements and activities through risk/KPI reports helps to identify risks that need mitigation. If the requirements are not being levied on the supply chain, then the threat to the customer increases. This threat increases as an organization uses more CSP services, and it is dependent on individual CSPs and their supply chain policies.
upvoted 1 times
...
This section is not available anymore. Please use the main Exam Page.CCAK Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Auditor2020
1 month, 2 weeks agosai_murthy
9 months ago