Certified Cloud Security Professional (CCSP)Legal, Risk and ComplianceEasy

A small startup is utilizing a public cloud provider for all its IT infrastructure. To minimize operational costs while ensuring compliance with basic data protection regulations, the startup opts to use the CSP's native security services (e.g., IAM, encryption, logging) and relies on the CSP's shared responsibility model for infrastructure security. This approach BEST exemplifies which of the following strategies for cloud compliance?

  1. AOutsourcing all compliance responsibilities to a third-party auditor.
  2. BLeveraging CSP-native security and compliance capabilities.
  3. CAdopting a multi-cloud vendor lock-in strategy.
  4. DImplementing a hybrid cloud compliance framework.
Show answer & explanation

Correct answer: B. Leveraging CSP-native security and compliance capabilities.

This strategy involves using the security and compliance features built into the cloud service provider's platform, often aligning with the shared responsibility model, to meet regulatory obligations cost-effectively. It leverages the CSP's investment in security infrastructure.

Why the other options are wrong

  • A. Compliance cannot be fully outsourced; the customer always retains ultimate responsibility, even if using auditors or CSP features.
  • C. Vendor lock-in is a risk, not a compliance strategy, and multi-cloud implies multiple CSPs, which is not stated as the primary approach.
  • D. A hybrid cloud framework involves both on-premises and cloud resources, which is not the scenario described.

Leveraging CSP-Native Compliance

A strategy where cloud customers utilize the built-in security features, compliance certifications, and shared responsibility model of their Cloud Service Provider to meet their own regulatory and security obligations.

  • Cost-effective for startups and smaller organizations.
  • Relies on CSP's continuous investment in security.
  • Requires understanding the shared responsibility model.

Memory trick: For lean compliance, CSP-native features are the effective alliance.

More Legal, Risk and Compliance questions