Certificate of Cloud Auditing Knowledge (CCAK) — Question 77
Changes to which of the following will MOST likely influence the expansion or reduction of controls required to remediate the risk arising from changes to an organization’s SaaS vendor?
Answer options
- A. Risk exceptions policy
- B. Contractual requirements
- C. Risk appetite
- D. Board oversight
Correct answer: B
Explanation
The correct answer is B, as contractual requirements directly outline the obligations and expectations between the organization and the SaaS vendor, influencing control measures. The other options, while important, do not specifically dictate the necessary controls related to vendor changes in the same direct manner that contractual obligations do.