Certificate of Cloud Auditing Knowledge (CCAK) — Question 106
When capturing compliance objectives within an organization’s cloud policy, it is MOST important for stakeholders to:
Answer options
- A. take into consideration the organization’s risk appetite.
- B. measure the operating effectiveness of existing controls.
- C. seek input from external subject matter experts.
- D. follow a structured decision-making process.
Correct answer: A
Explanation
The correct answer is A because understanding the organization’s risk appetite is crucial for aligning compliance objectives with the overall risk management strategy. Options B, C, and D, while important, do not prioritize the organization's risk tolerance, which is fundamental in shaping effective compliance policies.