Certified Cloud Security Professional (CCSP)Legal, Risk and ComplianceEasy
A cloud customer is preparing for a regulatory compliance audit regarding their use of a public cloud provider. The auditor requests evidence of the CSP's adherence to industry-specific data protection standards. Which of the following documents would BEST demonstrate the CSP's commitment and capability in meeting these standards?
- AThe cloud customer's internal security policy.
- BA copy of the Service Level Agreement (SLA) between the customer and the CSP.
- CThe CSP's marketing brochure highlighting their security features.
- DA third-party audit report (e.g., SOC 2 Type 2, ISO 27001 certification).
Show answer & explanationAnswer & explanation
Correct answer: D. A third-party audit report (e.g., SOC 2 Type 2, ISO 27001 certification).
Third-party audit reports provide independent assurance of a CSP's security controls and compliance with various standards, making them the most effective evidence for a regulatory audit.
Why the other options are wrong
- A. This document reflects the customer's policies, not the CSP's adherence to standards.
- B. An SLA outlines contractual obligations but does not provide detailed evidence of security controls or compliance adherence.
- C. Marketing materials are promotional and do not serve as verifiable evidence for an audit.
Third-Party Audit Reports
Independent evaluations of a cloud service provider's security controls and processes against recognized standards, offering assurance to customers and auditors.
- Provide objective evidence of compliance.
- Examples include SOC 2 Type 2, ISO 27001.
- Crucial for regulatory compliance and due diligence.
Memory trick: To prove compliance, an independent report is the best defense.