CCSP - Legal, Risk and Compliance - Section 6.1

Articulate legal requirements and unique risks within the cloud environment.

Conflicting international legislation, evaluation of legal risks specific to cloud computing, legal frameworks and guidelines, eDiscovery, and forensic requirements.

conflicting international legislationeDiscoveryISO/IEC 27050Cloud Security Alliance guidancejurisdiction and data sovereignty

Practice question for this objective

Free sampleLegal, Risk and Compliancemedium

A Frankfurt-based insurer runs its claims platform as a SaaS subscription. The provider stores personal data across public-cloud regions in Germany and the United States. A United States court issues a subpoena to the provider demanding claims records that include EU residents' personal data, and EU law restricts that transfer. What is the insurer's central legal risk in this situation?

  • AVendor lock-in, because the SaaS provider controls the claims data format and the insurer cannot readily migrate to another platform
  • BLoss of the availability of the claims records, since responding to the subpoena will take the SaaS platform offline for the insurer's users
  • CConflicting international legislation, where complying with the foreign disclosure order would breach the data-protection law governing the same records Correct
  • DWeak encryption of the claims data at rest, which would let the requesting court read the records without the insurer's cooperation
Recognise that conflicting international legislation, where one jurisdiction compels disclosure another forbids, is a defining legal risk of cross-border cloud data. When a controller is bound by one country's disclosure order and another country's transfer prohibition over the same records, the obligations cannot both be satisfied, and that conflict of laws is the exposure rather than any single technical control failing.

Why A is wrong: Lock-in is a real cloud concern about portability and exit, but the scenario turns on incompatible legal obligations across borders, not on the difficulty of switching providers.

Why B is wrong: Producing records for discovery does not require an outage, so availability is not the exposure; the harm is legal liability for whichever law the insurer ends up breaching.

Why C is correct: Correct: the defining cloud legal risk here is one jurisdiction compelling disclosure while another jurisdiction prohibits the transfer, forcing the controller into an unavoidable conflict of laws.

Why D is wrong: Encryption strength is a control question that a candidate may reach for, but a lawful subpoena compels the plaintext or the keys regardless, and the conflict is jurisdictional rather than cryptographic.

See more CCSP practice questions, answers explained.

More in this domain

Back to all Legal, Risk and Compliance objectives, or the CCSP cert hub.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.