Certificate of Cloud Auditing Knowledge (CCAK) — Question 128
How should an auditor deal with auditing a cloud service provider’s suppliers?
Answer options
- A. Share the responsibility with the cloud provider to audit the cloud provider’s suppliers.
- B. No action is necessary, as any aspect of the cloud supplier program is the cloud provider’s responsibility.
- C. Audit the effectiveness of the cloud provider’s supplier management program.
- D. No action necessary, as the cloud provider’s suppliers are not part of the compliance program.
Correct answer: C
Explanation
The correct answer is C, as auditors should assess the effectiveness of the cloud provider's supplier management program to ensure compliance and risk management. Options A and B misinterpret the auditor's role, suggesting a lack of responsibility, while D incorrectly assumes that suppliers are irrelevant to the compliance program.