In relation to testing business continuity management and operational resilience, an auditor should review which of the following database documentation?
One of the control specifications in the Cloud Controls Matrix (CCM) states that "independent reviews and assessments shall be performed at least annually to ensure that the organization addresses nonconformities of established policies, standards, procedures, and compliance obligation." Which of the following controls under the Audit Assurance and Compliance domain does this match to?
The MOST important factor to consider when implementing cloud-related controls is the:
Which of the following is MOST important to ensure effective operationalization of cloud security controls?
What is an advantage of using dynamic application security testing (DAST) over static application security testing (SAST) methodology?
The PRIMARY purpose of Open Certification Framework (OCF) for the CSA STAR program is to:
Which of the following cloud service provider activities MUST obtain a client's approval?
A business unit introducing cloud technologies to the organization without the knowledge or approval of the appropriate governance function is an example of: