Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 2 fuera de 13 páginas
Examen

WGU Managing Cloud Security D320 (C838) Laws, Regulations, And Organizations: Questions/Answers

Document preview thumbnail
Vista previa 2 fuera de 13 páginas

WGU Managing Cloud Security D320 (C838) Laws, Regulations, And Organizations: Questions/Answers

Vista previa del contenido

WGU Managing Cloud Security D320 (C838) Laws,
Regulations, And Organizations: Questions/Answers

(ISC)2 - International Information System Security Certification Consortium
Right Ans - A security certification granting organization that has a long
history of certifications that were difficult to get. This difficulty has made their
certificates seen as having higher value in the industry.

(ISC)2 Cloud Secure Data Life Cycle Right Ans - Based on CSA Guidance. 1.
Create; 2. Store; 3. Use; 4. Share; 5. Archive; 6. Destroy.

(SAS) 70 Right Ans - _____ was a recognized standard of the American
Institute of Certified Public Accountants (AICPA) in response to the issues that
also lead to Sarbanes-Oxley (SOX). Deprecated in 2011 by the Statement on
Standards for Attestation Engagements (SSAE) No. 16.

AICPA Right Ans - established SAS 70 and later SAAE 16.

AICPA Right Ans - American Institute of Certified Public Accountants

Organizational Normative Framework (ONF) Right Ans - Concepts of ISO
27034. There is only one _____ for an organization but potentially as many
ANF's as applications.

ASHRAE - American Society of Heating, Refrigerating and Air-Conditioning
Engineers Right Ans - a professional association seeking to advance
heating, ventilation, air conditioning and refrigeration systems design and
construction.

Biba Right Ans - an access control model designed to preserve data
integrity. It has 3 goals. Maintain internal and external consistency; prevent
unauthorized data modification even by authorized parties; prevent data
modification by unauthorized individuals.

Capability Maturity Model (CMM) Right Ans - a development model where
the maturity relates to the formality and optimization of processes. When
applied to cloud security it would focus on those aspects as they relate to
cloud security.

, Child Online Protection Act (COPA) Right Ans - An attempt to restrict
access by minors to material defined as harmful to minors. A permanent
injunction against the law in 2009.

Cloud Access Security Brokers (CASBs) Right Ans - monitors network
activity between users and cloud applications and enforces security policy and
blocking malware.

Cloud Security Alliance (CSA) Right Ans - publishes the Notorious Nine: 1)
Data breaches; 2) Data Loss; 3) Account service traffic hijacking; 4) Insecure
Interfaces and APIs; 5) Denial of Service; 6) Malicious Insiders; 7) Abuse of
Cloud Services; 8) Insufficient Due Diligence; 9) Shared technology
Vulnerabilities. There are also implications and controls associated with each.

CSA STAR - Cloud Security Alliance (CSA) Security, Trust, and Assurance
Registry (STAR) Right Ans - _______ uses the Consensus Assessments
Initiative Questionnaire (CAIQ), Cloud Controls Matrix (CCM), and GDPR Self-
Assessment as inputs to certify an organization to Level 1.

Level 2 integrates the CSA Cloud Controls Matrix and the AICPA Trust Service
Principles - AT 101 for STAR attestation.

STAR Certification for level to uses the CSA Cloud Controls Matrix and the
requirements of the ISO/IEC 27001:2013 management system standard
together with the CSA Cloud Controls Matrix.

Certification certificates follow normal ISO/IEC 27001 protocol for a 3rd party
assessment.

Cloud Security Alliance Cloud Controls Matrix (CSA CCM) Right Ans -
Composed of 17 domains covering key elements of cloud. It contains 170
objectives within the domains. They integrate with the STAR program.

COBIT or Control Objectives for Information and Related Technologies
Right Ans - a framework for IT governance and management. Initially used to
achieve compliance with Sarbanes-Oxley and focused on IT controls. Since
2019 the emphasis has shifted to information governance. It is focused on
these 5 principles: 1: Meeting Stakeholder Needs; 2: Covering the Enterprise

Información del documento

Subido en
29 de diciembre de 2024
Número de páginas
13
Escrito en
2024/2025
Tipo
Examen
Contiene
Preguntas y respuestas
$12.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
StudyHall
3.8
(231)
Vendido
1348
Seguidores
825
Artículos
17221
Última venta
20 horas hace




Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes