Certificate of Cloud Auditing Knowledge (CCAK) — Question 81
A cloud auditor observed that just before a new software went live, the librarian transferred production data to the test environment to confirm the new software can work in the production environment. What additional control should the cloud auditor check?
Answer options
- A. Approval of the change by the change advisory board
- B. Explicit documented approval from all customers whose data is affected
- C. Training for the librarian
- D. Verification that the hardware of the test and production environments are compatible
Correct answer: A
Explanation
The correct answer is A because approval from the change advisory board is essential to ensure that changes are properly vetted and authorized. Options B and C, while important, do not directly relate to the control over the change process, and D is not necessary as the focus is on the approval of the change rather than hardware compatibility.