A media company operates a hybrid-cloud video pipeline and wants to certify that its service management processes for incident, change and problem handling meet a recognised, auditable international standard that customers can rely on in contracts. Which standard should it pursue certification against?
- AISO/IEC 20000-1, to certify a service management system covering those operational processes Correct
- BNIST SP 800-145, to formalise the definitions of its cloud service and deployment models
- CISO/IEC 27018, to demonstrate protection of personally identifiable information in the public cloud
- DISO/IEC 27017, to adopt the cloud-specific information security controls for the pipeline
Why A is correct: ISO/IEC 20000-1 specifies requirements for a service management system, including incident, change and problem management, and organisations can be certified against it, matching the stated need.
Why B is wrong: NIST SP 800-145 defines the essential characteristics, service models and deployment models of cloud computing; it is a definitional document, not a certifiable service management standard.
Why C is wrong: ISO/IEC 27018 gives a code of practice for protecting PII processed in public clouds; it addresses privacy controls rather than the management system for incident, change and problem processes.
Why D is wrong: ISO/IEC 27017 provides cloud-specific security control guidance and is tempting for a cloud pipeline, but it targets information security controls, not certification of the service management processes named in the scenario.