Certified Cloud Security Professional (CCSP)Legal, Risk and ComplianceEasy

A cloud customer is preparing for a regulatory compliance audit regarding their use of a public cloud provider. The auditor requests evidence of the CSP's adherence to industry-specific data protection standards. Which of the following documents would BEST demonstrate the CSP's commitment and capability in meeting these standards?

  1. AThe cloud customer's internal security policy.
  2. BA copy of the Service Level Agreement (SLA) between the customer and the CSP.
  3. CThe CSP's marketing brochure highlighting their security features.
  4. DA third-party audit report (e.g., SOC 2 Type 2, ISO 27001 certification).
Show answer & explanation

Correct answer: D. A third-party audit report (e.g., SOC 2 Type 2, ISO 27001 certification).

Third-party audit reports provide independent assurance of a CSP's security controls and compliance with various standards, making them the most effective evidence for a regulatory audit.

Why the other options are wrong

  • A. This document reflects the customer's policies, not the CSP's adherence to standards.
  • B. An SLA outlines contractual obligations but does not provide detailed evidence of security controls or compliance adherence.
  • C. Marketing materials are promotional and do not serve as verifiable evidence for an audit.

Third-Party Audit Reports

Independent evaluations of a cloud service provider's security controls and processes against recognized standards, offering assurance to customers and auditors.

  • Provide objective evidence of compliance.
  • Examples include SOC 2 Type 2, ISO 27001.
  • Crucial for regulatory compliance and due diligence.

Memory trick: To prove compliance, an independent report is the best defense.

More Legal, Risk and Compliance questions