Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 76 discussion

Actual exam question from ISC's CISSP
Question #: 76
Topic #: 1
[All CISSP Questions]

An international organization has decided to use a Software as a Service (SaaS) solution to support its business operations. Which of the following compliance standards should the organization use to assess the international code security and data privacy of the solution?

  • A. Service Organization Control (SOC) 2
  • B. Information Assurance Technical Framework (IATF)
  • C. Health Insurance Portability and Accountability Act (HIPAA)
  • D. Payment Card Industry (PCI)
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
25cbb5f
7 months, 3 weeks ago
Selected Answer: A
The most suitable compliance standard for the international organization to assess both code security and data privacy of a SaaS solution is: A. Service Organization Control (SOC) 2 Here's why SOC 2 is the best fit: Focus on Security, Availability, and Privacy: SOC 2 reports are specifically designed to evaluate service providers, like SaaS vendors, on controls related to the security, availability, processing integrity, confidentiality, and privacy of the systems they use to process customers' data. International Applicability: While developed by the American Institute of Certified Public Accountants (AICPA), SOC 2 is widely recognized internationally and often requested by organizations worldwide. Flexibility: SOC 2 allows specifying the Trust Services Criteria (security, privacy, etc.) that are most relevant to the organization's needs. B. Information Assurance Technical Framework (IATF): IATF is primarily used within US government agencies. It might have relevance in limited contexts, but it's less common for commercial business purposes.
upvoted 2 times
...
AMANSUNAR
1 year ago
Selected Answer: A
The Information Assurance Technical Framework (IATF) is not a widely recognized standard for assessing the security and privacy aspects of cloud computing or Software as a Service (SaaS) solutions. The IATF is not as commonly associated with international code security and data privacy in the context of cloud services. For a more widely accepted and relevant standard for assessing the security and privacy of a SaaS solution, Service Organization Control (SOC) 2 is a more appropriate choice.
upvoted 1 times
...
Ukpes
1 year ago
SOC2 standard is based on the following trust services criteria: security, data privacy, confidentiality, process integrity, and availability.
upvoted 1 times
...
BoyBastos
1 year, 2 months ago
Selected Answer: A
SOC2 is right
upvoted 2 times
...
Bach1968
1 year, 4 months ago
Selected Answer: B
If the organization is specifically concerned with international code security and data privacy, the Information Assurance Technical Framework (IATF) would indeed be a more appropriate compliance standard to assess the solution. The IATF is a framework developed by the International Organization for Standardization (ISO) to provide guidelines for assessing the security and privacy aspects of information technology systems. It covers various areas such as risk management, security controls, and data privacy. While SOC 2 focuses more broadly on the overall security and privacy controls of service providers, the IATF specifically addresses the security and privacy of information technology systems, making it more suitable for assessing the code security and data privacy of the SaaS solution in an international context. Therefore, the organization should use the IATF to assess the international code security and data privacy of the SaaS solution.
upvoted 1 times
...
HughJassole
1 year, 5 months ago
D: Payment Card Industry. SOC2 is a report, not a standard. "The PCI Security Standards Council (PCI SSC) is a global forum that brings together payments industry stakeholders to develop and drive adoption of data security standards and resources for safe payments worldwide." https://www.pcisecuritystandards.org/
upvoted 1 times
...
dmo_d
1 year, 6 months ago
Selected Answer: A
A it is. B and C are US only. D is too specific (to financial businesses).
upvoted 1 times
...
Dee83
1 year, 10 months ago
A. Service Organization Control (SOC) 2 would be the most appropriate compliance standard for an international organization to use to assess the international code security and data privacy of a Software as a Service (SaaS) solution.
upvoted 2 times
jackdryan
1 year, 6 months ago
A is correct
upvoted 1 times
...
...
Firedragon
2 years ago
Selected Answer: A
A. The question is asking "international", IATF is US only, SOC2 is the answer.
upvoted 3 times
...
rootic
2 years ago
Selected Answer: A
it's A
upvoted 1 times
...
pingundas
2 years, 1 month ago
@ Humongous1593, I asked that question the support and got this answer: ______________________________________________________ Our answers are verified by our experts If the given answer is not correct then you can go with user voted ones. ______________________________________________________
upvoted 3 times
...
kptest12
2 years, 1 month ago
Selected Answer: A
Its SOC2 which has Privacy, confidentiality , security, availability and process integrity
upvoted 2 times
...
Humongous1593
2 years, 1 month ago
Selected Answer: A
A, why does this thing choose the wrong answer 90% of the time. I don't get it.
upvoted 3 times
CharlesL
2 years, 1 month ago
https://ntrl.ntis.gov/NTRL/dashboard/searchResults/titleDetail/ADA606355.xhtml
upvoted 1 times
...
Jay327
2 years ago
I thought I only felt this way :)
upvoted 1 times
...
...
DERCHEF2009
2 years, 2 months ago
Selected Answer: A
Yes its A
upvoted 4 times
...
stickerbush1970
2 years, 2 months ago
Selected Answer: A
Agree with A
upvoted 3 times
...
CuteRabbit168
2 years, 2 months ago
Selected Answer: A
Obvious SOC 2
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...