Which of the cloud cross-cutting aspects relates to the oversight of processes and systems, as well as to ensuring their compliance with specific policies and regulations?
The OSG says it's governance on page 20. Auditability is a subset of governance. But like with many of these situations, the "right" answer is not necessarily the "correct" answer.
Regulatory Compliance:
Regulatory compliance is an organization’s requirement to adhere to relevant laws, regulations, guidelines, and specifications relevant to its business, specifically dictated by
the nature, operations, and functions it provides or utilizes to its customers.
Governance role is to set the directions in form of policies, standards, and guidelines. Management role is delivery based on processes & procedures that follow the policies, standards, and guidelines. Audit role is to review & inspect that delivery conforms to the policies, standards, and guidelines. Thus, answer is D & not A.
It says oversight.. which is governance. Auditing is not oversight.. but then it says “ensuring their compliance..” that would be audit. I’d still pick D
Auditability allows for users and the organization to access, report, and obtain evidence of
actions, controls, and processes that were performed or run by a specified user.
D is correct:
Cloud Cross-Cutting Aspects: These cross-cutting aspects include security, interoperability, portability, reversibility, privacy, availability, governance, performance, service levels, service level agreements, auditability and regulatory aspects
Auditability isn't one of the cross cutting aspects. They are:
Security, Interoperability, Portability, Reversibility, Privacy, Availability and Governance
Yes, it is. It is at the top of the list. Check ISO 17789. I know the books don't list it.
Cross-cutting aspects include:
• auditability (clause 8.5.2);
• availability (clause 8.5.3);
• governance (clause 8.5.4);
• interoperability (clause 8.5.5);
• maintenance and versioning (clause 8.5.6);
• performance (clause 8.5.7);
• portability (clause 8.5.8);
• protection of personally identifiable information (clause 8.5.9);
• regulatory;
• resiliency (clause 8.5.10);
• reversibility (clause 8.5.11);
• security (clause 8.5.12);
• service levels and service level agreement (clause 8.5.13).
Correct answer: D
Most leading cloud providers supply their customers with a good deal of auditing,
including reports and evidence that show user activity, compliance with controls and
regulations, systems and processes that run and an explanation of what they do, as well
as information, data access, and modification records.
Audits are done to make sure controls and processes do what they are supposed to do, and that the Org is compliant with regulations.
upvoted 1 times
...
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
TraceSplice
8Â months, 1Â week agoFosca
10Â months, 1Â week agoDarln
10Â months agoTheGinjaNinja
1Â year, 7Â months agoPika26
1Â year, 7Â months agoBrittle
1Â year, 9Â months agoDERCHEF2009
2Â years, 1Â month agoserget12
2Â years, 1Â month agosamsom
2Â years, 4Â months agoaxman832005
2Â years, 9Â months agoaxman832005
2Â years, 9Â months agoSeke
3Â years, 2Â months agoVertho
3Â years, 11Â months agoHCL
4Â years agokjjcraigskel
4Â years, 1Â month agoAhbey_911
3Â years, 9Â months agoichnos
4Â years, 2Â months agocthd
4Â years, 2Â months agoCL888
4Â years, 2Â months ago