An IS auditor is mapping controls for a Software as a Service customer relationship management platform against an industry framework so that complementary user entity controls can be tested. Which framework is MOST appropriate for the auditor to reference when evaluating cloud-specific control coverage?
- AThe Cloud Security Alliance Cloud Controls Matrix, which maps cloud-specific control domains across provider and customer responsibilities and aligns to multiple compliance regimes. Correct
- BThe ISO/IEC 20000 service management standard, which prescribes service-level objectives and incident handling for outsourced operations across all hosting models.
- CThe Payment Card Industry Data Security Standard, which sets out cardholder data protection requirements that bind every SaaS provider regardless of the data it processes.
- DThe NIST Cybersecurity Framework Implementation Tiers, which describe organisational maturity in identifying, protecting, detecting, responding and recovering from cyber events.
Why A is correct: The CCM is purpose-built for cloud assurance and explicitly delineates provider and customer obligations, giving the auditor a structured basis to identify complementary user entity controls during testing.
Why B is wrong: ISO/IEC 20000 covers service management generally and is not cloud-specific; the candidate may select it because SaaS feels like outsourcing, but it lacks the responsibility split the CCM provides.
Why C is wrong: PCI DSS applies only when cardholder data is in scope and is not a general cloud control framework; assuming universal applicability is a common scope error among candidates.
Why D is wrong: The CSF is a strategic risk management tool and the tiers describe maturity rather than control coverage, so it does not give the auditor the cloud-specific control catalogue required here.