Which statement about compliance responsibilities and ownership of accountability is correct?
A.
Organizations may be able to transfer their accountability for compliance with various regulatory requirements to their CSPs, but they retain the ownership of responsibility.
B.
Organizations may be able to transfer their responsibility for compliance with various regulatory requirements to their CSPs, but they retain the ownership of accountability.
C.
Organizations may transfer their responsibility and accountability for compliance with various regulatory requirements to their CSPs.
D.
Organizations are not able to transfer their responsibility nor accountability for compliance with various regulatory requirements to their CSPs.
p. 49 CCAK Study Guide - In the cloud, responsibility for some actions (e.g., implementation of security controls) can be transferred to the CSP; however, the cloud customer is ultimately accountable.
The correct statement is:
**B. Organizations may be able to transfer their responsibility for compliance with various regulatory requirements to their CSPs, but they retain the ownership of accountability.**
In the context of cloud services, while organizations can delegate certain compliance responsibilities to their cloud service providers (CSPs), such as managing the security of the cloud infrastructure, the ultimate accountability for compliance with regulatory requirements remains with the organizations themselves. This means that even though CSPs may handle specific tasks or controls, the organization is ultimately accountable for ensuring that all compliance requirements are met.
CCAK P# 65 With the introduction of the cloud, customers transfer to CSPs not only some IT stacks, but also some responsibility for policies, standards, business requirements, and legal and regulatory requirements. Although security is a shared responsibility between the cloud service provider and the organization, with responsibilities distributed across the stack, compliance accountability remains with the customer.
"Shared responsibility model - The compliance responsibility between cloud customer and the cloud service provider based on the degree of control each party has over the architecture stack" p. 408 (glossary) CCAK study guide
upvoted 1 times
...
This section is not available anymore. Please use the main Exam Page.CCAK Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
ME79
Highly Voted 1 year, 8 months agoAuditor2020
Most Recent 2 months, 1 week agosai_murthy
9 months, 1 week agoDawnMBentley
1 year, 10 months ago