Which of the following is the MOST efficient way for a customer organization to minimize the risk from a cloud service provider’s aggressive product release strategy that could cause the customer to deviate from its compliance obligations?
A.
Including a break clause in the provider processing contract to be activated in the event of significant product change
B.
Developing multiple lines of communication with the provider that provide visibility into upcoming changes to the product
C.
Maintaining a failover processing agreement with another provider offering a similar product
D.
Requiring that the source code for the provider product be held in escrow with an independent third party
B. Developing multiple lines of communication with the provider that provide visibility into upcoming changes to the product
Developing multiple lines of communication with the cloud service provider is the most efficient way to stay informed about upcoming changes, allowing the customer organization to proactively assess and manage any potential impacts on compliance obligations. This approach ensures that the organization can plan and adapt to changes in a timely manner, adjusting their compliance strategies as needed.
While options A, C, and D offer potential mitigations, they are more reactive and may involve significant costs or complexities. Establishing open and ongoing communication with the provider is a proactive strategy that helps the organization to continuously align its compliance efforts with the provider's product roadmap.
P# 77 In general, cloud agreements require cloud customers to accept changes made by CSPs as they evolve their services. Those modifications can have drastic consequences for certain customers and must be monitored to ensure continuity of the customer’s operations. For example, the retirement of a feature might break a key functionality on which the customer depends, or it might impact user-facing controls.
The assessor should determine whether the cloud customer has an effective process in place to track and assess the impact of CSP changes in a timely way. The CSP agreement should be checked to determine whether customers are obliged to upgrade to the latest version of the service or if they can continue using the older version. If the cloud agreement allows the CSP to sunset any service within a set time, the customer may need to factor this risk into its own change plans.
upvoted 1 times
...
This section is not available anymore. Please use the main Exam Page.CCAK Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Auditor2020
1 month, 1 week agosai_murthy
8 months, 3 weeks ago