CCSP - Cloud Security Operations - Section 5.3

Implement operational controls and standards.

Change, continuity, information security, continual service improvement, incident, problem, release, deployment, configuration, service level, availability and capacity management, framed by ITIL and ISO/IEC 20000-1.

change managementincident managementproblem managementconfiguration managementITILISO/IEC 20000-1

Practice question for this objective

Free sampleCloud Security Operationsmedium

A media company operates a hybrid-cloud video pipeline and wants to certify that its service management processes for incident, change and problem handling meet a recognised, auditable international standard that customers can rely on in contracts. Which standard should it pursue certification against?

  • AISO/IEC 20000-1, to certify a service management system covering those operational processes Correct
  • BNIST SP 800-145, to formalise the definitions of its cloud service and deployment models
  • CISO/IEC 27018, to demonstrate protection of personally identifiable information in the public cloud
  • DISO/IEC 27017, to adopt the cloud-specific information security controls for the pipeline
Map service management certification of incident, change and problem processes to ISO/IEC 20000-1 rather than security or privacy standards. ISO/IEC 20000-1 is the specification for a service management system and is the standard organisations certify against for processes such as incident, change and problem management, whereas the ISO/IEC 27000-series and NIST documents cited address security, privacy or definitions instead.

Why A is correct: ISO/IEC 20000-1 specifies requirements for a service management system, including incident, change and problem management, and organisations can be certified against it, matching the stated need.

Why B is wrong: NIST SP 800-145 defines the essential characteristics, service models and deployment models of cloud computing; it is a definitional document, not a certifiable service management standard.

Why C is wrong: ISO/IEC 27018 gives a code of practice for protecting PII processed in public clouds; it addresses privacy controls rather than the management system for incident, change and problem processes.

Why D is wrong: ISO/IEC 27017 provides cloud-specific security control guidance and is tempting for a cloud pipeline, but it targets information security controls, not certification of the service management processes named in the scenario.

See more CCSP practice questions, answers explained.

More in this domain

Back to all Cloud Security Operations objectives, or the CCSP cert hub.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.