CISA - Protection of Information Assets - Section 5.1

Assess security of cloud and virtualized environments and of mobile, wireless and Internet-of-Things devices.

Describe the shared-responsibility model for cloud security and the additional attack surface introduced by virtualisation, mobile and wireless deployments. Assess the security of IoT devices and cloud-hosted environments, identifying controls that address misconfigurations, insecure communications and inadequate patching.

cloud securityvirtualizationmobile and wireless securityIoT devices

Practice question for this objective

Free sampleProtection of Information Assetshard

An IS auditor is mapping controls for a Software as a Service customer relationship management platform against an industry framework so that complementary user entity controls can be tested. Which framework is MOST appropriate for the auditor to reference when evaluating cloud-specific control coverage?

  • AThe Cloud Security Alliance Cloud Controls Matrix, which maps cloud-specific control domains across provider and customer responsibilities and aligns to multiple compliance regimes. Correct
  • BThe ISO/IEC 20000 service management standard, which prescribes service-level objectives and incident handling for outsourced operations across all hosting models.
  • CThe Payment Card Industry Data Security Standard, which sets out cardholder data protection requirements that bind every SaaS provider regardless of the data it processes.
  • DThe NIST Cybersecurity Framework Implementation Tiers, which describe organisational maturity in identifying, protecting, detecting, responding and recovering from cyber events.
Select the Cloud Security Alliance Cloud Controls Matrix as the framework that maps cloud control domains across provider and customer responsibilities. The CCM organises seventeen domains of cloud-specific controls and clearly indicates which controls are provider, customer or shared. That structure lets the IS auditor identify the complementary user entity controls that must be tested at the customer to rely on the provider's assurance report, which generic management standards do not support.

Why A is correct: The CCM is purpose-built for cloud assurance and explicitly delineates provider and customer obligations, giving the auditor a structured basis to identify complementary user entity controls during testing.

Why B is wrong: ISO/IEC 20000 covers service management generally and is not cloud-specific; the candidate may select it because SaaS feels like outsourcing, but it lacks the responsibility split the CCM provides.

Why C is wrong: PCI DSS applies only when cardholder data is in scope and is not a general cloud control framework; assuming universal applicability is a common scope error among candidates.

Why D is wrong: The CSF is a strategic risk management tool and the tiers describe maturity rather than control coverage, so it does not give the auditor the cloud-specific control catalogue required here.

See more CISA practice questions, answers explained.

More in this domain

Back to all Protection of Information Assets objectives, or the CISA cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.