Certificate of Cloud Auditing Knowledge (CCAK) — Question 75
An organization deploying the Cloud Control Matrix (CCM) to perform a compliance assessment will encompass the use of the “Corporate Governance Relevance” feature to filter out those controls:
Answer options
- A. relating to policies, processes, laws, regulations, and institutions conditioning the way an organization is managed, directed, or controlled.
- B. that can be either of a management or of a legal nature, therefore requiring an approval from the Change Advisory Board.
- C. that require the prior approval from the Board of Directors to be funded (for either make or buy), implemented, and reported on.
- D. that can be either of an administrative or of a technical nature, therefore requiring an approval from the Change Advisory Board.
Correct answer: A
Explanation
The correct answer, A, is accurate because it directly relates to the governance aspects that the Corporate Governance Relevance feature is designed to filter out. Options B, C, and D focus on approval processes or funding, which are not specifically aligned with the core governance relevance that CCM addresses.