CCSP - Cloud Concepts, Architecture and Design - Section 1.5

Evaluate Cloud Service Providers (CSP).

Verification against certification criteria and system/subsystem product certifications, including ISO/IEC 27017, the CSA STAR programme, SOC reporting, FedRAMP, and Common Criteria.

ISO/IEC 27017CSA STARSOC 1, SOC 2 and SOC 3FedRAMPCommon CriteriaFIPS 140-3

Practice question for this objective

Free sampleCloud Concepts, Architecture and Designmedium

A security architect is reviewing certifications a candidate cloud provider holds. She wants the certification that specifically extends an information security management system with cloud-specific control guidance for both providers and customers. Which certification best meets that need?

  • AISO/IEC 27017, which gives cloud-specific security control guidance for cloud service providers and cloud service customers. Correct
  • BISO/IEC 27018, which provides a code of practice for protecting personally identifiable information processed in public clouds.
  • CFIPS 140-3, which validates the security of cryptographic modules used to protect sensitive data.
  • DCommon Criteria, which evaluates the security assurance of a specific IT product against a protection profile.
Identify ISO/IEC 27017 as the cloud-specific security control code of practice covering providers and customers. ISO/IEC 27017 builds on the baseline information security controls by adding guidance for cloud service delivery, clarifying which security responsibilities fall to the provider and which to the customer, which is exactly what an architect assessing a cloud provider's control coverage needs.

Why A is correct: Correct. ISO/IEC 27017 supplements the ISMS control set with implementation guidance tailored to cloud services and assigns responsibilities across provider and customer, matching the requirement stated.

Why B is wrong: ISO/IEC 27018 is genuinely cloud-relevant, which makes it tempting, but it targets protection of PII in public clouds specifically rather than general cloud security control guidance for providers and customers.

Why C is wrong: FIPS 140-3 is a valid assurance standard but it validates cryptographic modules, not a cloud-wide security management control set, so it does not extend an ISMS with cloud control guidance.

Why D is wrong: Common Criteria evaluates individual products against protection profiles at an assurance level; it is product assurance, not organisation-level cloud security management guidance.

See more CCSP practice questions, answers explained.

More in this domain

Back to all Cloud Concepts, Architecture and Design objectives, or the CCSP cert hub.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.