Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Medium

A global organization uses Prisma Cloud to enforce compliance with GDPR across its AWS, Azure, and GCP environments. They need to create a custom compliance standard that maps specific Prisma Cloud policies to GDPR articles. Which of the following is the correct workflow to achieve this?

  1. AGo to Policies > Compliance > Add New Compliance Standard, then manually create and assign policies.
  2. BGo to Compliance > Custom Standards > Add New, then import GDPR-specific policies from a template.
  3. CGo to Policies > Policy Management > Create Custom Policy, then tag policies with 'GDPR'.
  4. DGo to Compliance > Standards > Create New Standard, then map existing Prisma Cloud policies.
Show answer & explanation

Correct answer: D. Go to Compliance > Standards > Create New Standard, then map existing Prisma Cloud policies.

In Prisma Cloud, custom compliance standards are created under 'Compliance > Standards'. Once a new standard is created, you can then map relevant Prisma Cloud policies (both default and custom) to the specific requirements or articles of that standard, such as GDPR.

Why the other options are wrong

  • A. The exact navigation path is incorrect; 'Policies > Compliance' is not where compliance standards are managed.
  • B. 'Custom Standards' is part of the 'Compliance' section, but the subsequent action of 'importing GDPR-specific policies from a template' is not the primary mechanism for standard creation and mapping.
  • C. Creating individual custom policies and tagging them is part of policy creation, not the process of establishing an overarching custom compliance standard that groups policies.

Prisma Cloud Custom Compliance Standards

Allows users to define new compliance frameworks and map existing Prisma Cloud policies to their specific requirements.

  • Extends Prisma Cloud's compliance reporting.
  • Maps to internal or external regulations (e.g., GDPR, HIPAA).
  • Provides a consolidated view of compliance posture against custom standards.

Memory trick: Compliance standards are built from 'standards' you 'create'.

More Cloud Security Posture Management (CSPM) questions