D320 (C838) Laws, Regulations, and
Organizations Questions With All Correct &
Verified Answers
1. (ISC)2 -
A security certification granting organization that has a long history of
Interna- tional
certifications that were diflcult to get. This diflculty has made their
Informa- tion
certificates seen as having higher value in the industry.
System Se-
curity
Certifica- tion
Consortium Based on CSA Guidance. 1. Create; 2. Store; 3. Use; 4. Share; 5. Archive;
Destroy.
2. (ISC)2 Cloud
Se- cure Data
Life Cy- cle
3. (SAS) 70 was a recognized standard of the American Institute of Certified Pub
Accountants (AICPA) in response to the issues that also lead to
Sarbanes-Oxley (SOX). Deprecated in 2011 by the Statement on
Standards for Attestation Engage- ments (SSAE) No. 16.
4. AICPA established SAS 70 and later SAAE 16.
5. AICPA American Institute of Certified Public Accountants
6. Organization neers
al Normative
Framework 8. Biba
(ONF)
7. ASHRAE - Amer-
ican Soci-
ety of
Heat-
ing,
Refrigerat- ing
and Air-Con-
ditioning Engi-
, D320 (C838) Laws, Regulations, and
Organizations Questions With All Correct &
Verified
Concepts of ISO Answers
27034. There is only
one
for an organization but
potentially as many
ANF's as applications.
a professional association
seeking to advance
heating, ventilation, air
condition- ing and
refrigeration systems
design and construction.
, D320 (C838) Laws, Regulations, and
Organizations Questions With All Correct &
Verified Answers
an access control model designed to preserve data integrity. It has 3
goals. Main- tain internal and external consistency; prevent
unauthorized data modification even by authorized parties; prevent data
modification by unauthorized individuals.
9. Capability
Matu- rity a development model where the maturity relates to the formality and
Model (CMM) optimization of processes. When applied to cloud security it would focus
on those aspects as they relate to cloud security.
10. Child Online An attempt to restrict access by minors to material defined as harmful
Protection to minors. A permanent injunction against the law in 2009.
Act (COPA)
11. Cloud Access monitors network activity between users and cloud applications and
Se- curity enforces security policy and blocking malware.
Brokers
(CASBs)
12. Cloud Security Al- publishes the Notorious Nine: 1) Data breaches; 2) Data Loss; 3) Accou
service
liance (CSA) traflc hijacking; 4) Insecure Interfaces and APIs; 5) Denial of Service; 6) Malicious
Insiders; 7) Abuse of Cloud Services; 8) Insuflcient Due Diligence; 9)
Shared technology Vulnerabilities. There are also implications and
controls associated with each.
13. CSA STAR - Cloud uses the Consensus Assessments Initiative Questionnaire (CAIQ),
Cloud
Security Alliance Controls Matrix (CCM), and GDPR Self-Assessment as inputs to certify an
(CSA) Security, organi- zation to Level 1.
Trust, and As-
surance Level 2 integrates the CSA Cloud Controls Matrix and the AICPA Trust Service
Registry Principles - AT 101 for STAR attestation.
(STAR)
STAR Certification for level to uses the CSA Cloud Controls Matrix and the require-
Organizations Questions With All Correct &
Verified Answers
1. (ISC)2 -
A security certification granting organization that has a long history of
Interna- tional
certifications that were diflcult to get. This diflculty has made their
Informa- tion
certificates seen as having higher value in the industry.
System Se-
curity
Certifica- tion
Consortium Based on CSA Guidance. 1. Create; 2. Store; 3. Use; 4. Share; 5. Archive;
Destroy.
2. (ISC)2 Cloud
Se- cure Data
Life Cy- cle
3. (SAS) 70 was a recognized standard of the American Institute of Certified Pub
Accountants (AICPA) in response to the issues that also lead to
Sarbanes-Oxley (SOX). Deprecated in 2011 by the Statement on
Standards for Attestation Engage- ments (SSAE) No. 16.
4. AICPA established SAS 70 and later SAAE 16.
5. AICPA American Institute of Certified Public Accountants
6. Organization neers
al Normative
Framework 8. Biba
(ONF)
7. ASHRAE - Amer-
ican Soci-
ety of
Heat-
ing,
Refrigerat- ing
and Air-Con-
ditioning Engi-
, D320 (C838) Laws, Regulations, and
Organizations Questions With All Correct &
Verified
Concepts of ISO Answers
27034. There is only
one
for an organization but
potentially as many
ANF's as applications.
a professional association
seeking to advance
heating, ventilation, air
condition- ing and
refrigeration systems
design and construction.
, D320 (C838) Laws, Regulations, and
Organizations Questions With All Correct &
Verified Answers
an access control model designed to preserve data integrity. It has 3
goals. Main- tain internal and external consistency; prevent
unauthorized data modification even by authorized parties; prevent data
modification by unauthorized individuals.
9. Capability
Matu- rity a development model where the maturity relates to the formality and
Model (CMM) optimization of processes. When applied to cloud security it would focus
on those aspects as they relate to cloud security.
10. Child Online An attempt to restrict access by minors to material defined as harmful
Protection to minors. A permanent injunction against the law in 2009.
Act (COPA)
11. Cloud Access monitors network activity between users and cloud applications and
Se- curity enforces security policy and blocking malware.
Brokers
(CASBs)
12. Cloud Security Al- publishes the Notorious Nine: 1) Data breaches; 2) Data Loss; 3) Accou
service
liance (CSA) traflc hijacking; 4) Insecure Interfaces and APIs; 5) Denial of Service; 6) Malicious
Insiders; 7) Abuse of Cloud Services; 8) Insuflcient Due Diligence; 9)
Shared technology Vulnerabilities. There are also implications and
controls associated with each.
13. CSA STAR - Cloud uses the Consensus Assessments Initiative Questionnaire (CAIQ),
Cloud
Security Alliance Controls Matrix (CCM), and GDPR Self-Assessment as inputs to certify an
(CSA) Security, organi- zation to Level 1.
Trust, and As-
surance Level 2 integrates the CSA Cloud Controls Matrix and the AICPA Trust Service
Registry Principles - AT 101 for STAR attestation.
(STAR)
STAR Certification for level to uses the CSA Cloud Controls Matrix and the require-