Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 13 pages
Exam (elaborations)

WGU Managing Cloud Security D320 (C838) Laws, Regulations, And Organizations: Questions/Answers

Document preview thumbnail
Preview 2 out of 13 pages

WGU Managing Cloud Security D320 (C838) Laws, Regulations, And Organizations: Questions/Answers

Content preview

WGU Managing Cloud Security D320 (C838) Laws,
Regulations, And Organizations: Questions/Answers

(ISC)2 - International Information System Security Certification Consortium
Right Ans - A security certification granting organization that has a long
history of certifications that were difficult to get. This difficulty has made their
certificates seen as having higher value in the industry.

(ISC)2 Cloud Secure Data Life Cycle Right Ans - Based on CSA Guidance. 1.
Create; 2. Store; 3. Use; 4. Share; 5. Archive; 6. Destroy.

(SAS) 70 Right Ans - _____ was a recognized standard of the American
Institute of Certified Public Accountants (AICPA) in response to the issues that
also lead to Sarbanes-Oxley (SOX). Deprecated in 2011 by the Statement on
Standards for Attestation Engagements (SSAE) No. 16.

AICPA Right Ans - established SAS 70 and later SAAE 16.

AICPA Right Ans - American Institute of Certified Public Accountants

Organizational Normative Framework (ONF) Right Ans - Concepts of ISO
27034. There is only one _____ for an organization but potentially as many
ANF's as applications.

ASHRAE - American Society of Heating, Refrigerating and Air-Conditioning
Engineers Right Ans - a professional association seeking to advance
heating, ventilation, air conditioning and refrigeration systems design and
construction.

Biba Right Ans - an access control model designed to preserve data
integrity. It has 3 goals. Maintain internal and external consistency; prevent
unauthorized data modification even by authorized parties; prevent data
modification by unauthorized individuals.

Capability Maturity Model (CMM) Right Ans - a development model where
the maturity relates to the formality and optimization of processes. When
applied to cloud security it would focus on those aspects as they relate to
cloud security.

, Child Online Protection Act (COPA) Right Ans - An attempt to restrict
access by minors to material defined as harmful to minors. A permanent
injunction against the law in 2009.

Cloud Access Security Brokers (CASBs) Right Ans - monitors network
activity between users and cloud applications and enforces security policy and
blocking malware.

Cloud Security Alliance (CSA) Right Ans - publishes the Notorious Nine: 1)
Data breaches; 2) Data Loss; 3) Account service traffic hijacking; 4) Insecure
Interfaces and APIs; 5) Denial of Service; 6) Malicious Insiders; 7) Abuse of
Cloud Services; 8) Insufficient Due Diligence; 9) Shared technology
Vulnerabilities. There are also implications and controls associated with each.

CSA STAR - Cloud Security Alliance (CSA) Security, Trust, and Assurance
Registry (STAR) Right Ans - _______ uses the Consensus Assessments
Initiative Questionnaire (CAIQ), Cloud Controls Matrix (CCM), and GDPR Self-
Assessment as inputs to certify an organization to Level 1.

Level 2 integrates the CSA Cloud Controls Matrix and the AICPA Trust Service
Principles - AT 101 for STAR attestation.

STAR Certification for level to uses the CSA Cloud Controls Matrix and the
requirements of the ISO/IEC 27001:2013 management system standard
together with the CSA Cloud Controls Matrix.

Certification certificates follow normal ISO/IEC 27001 protocol for a 3rd party
assessment.

Cloud Security Alliance Cloud Controls Matrix (CSA CCM) Right Ans -
Composed of 17 domains covering key elements of cloud. It contains 170
objectives within the domains. They integrate with the STAR program.

COBIT or Control Objectives for Information and Related Technologies
Right Ans - a framework for IT governance and management. Initially used to
achieve compliance with Sarbanes-Oxley and focused on IT controls. Since
2019 the emphasis has shifted to information governance. It is focused on
these 5 principles: 1: Meeting Stakeholder Needs; 2: Covering the Enterprise

Document information

Uploaded on
December 29, 2024
Number of pages
13
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$12.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
StudyHall
3.8
(231)
Sold
1348
Followers
825
Items
17221
Last sold
21 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions