Certificate of Cloud Auditing Knowledge (CCAK) — Question 3

Which of the following controls framework should the cloud customer use to assess the overall security risk of a cloud provider?

Answer options

Correct answer: B

Explanation

The Cloud Control Matrix (CCM) is specifically designed for assessing the security posture of cloud providers, making it the most suitable choice for cloud customers. The other options, such as SOC reports, focus on specific audit requirements rather than providing a comprehensive framework for security risk assessment in the cloud context.