CCSP - Legal, Risk and Compliance - Section 6.5

Understand outsourcing and cloud contract design.

Business requirements such as service level agreements and master service agreements, vendor management, contract management including right to audit and termination, and supply chain management.

service level agreement (SLA)master service agreement (MSA)right to auditvendor managementISO/IEC 27036

Practice question for this objective

Free sampleLegal, Risk and Compliancemedium

A cloud customer wants to select the standard that provides a code of practice for protecting personally identifiable information processed by public cloud providers acting as processors. Which standard is the correct choice?

  • AISO/IEC 27018, which provides a code of practice for protecting PII in public clouds acting as processors. Correct
  • BISO/IEC 27017, which provides cloud-specific information security controls guidance.
  • CISO/IEC 27001, which specifies requirements for an information security management system.
  • DNIST SP 800-145, which provides the reference definition of cloud computing.
Identify ISO/IEC 27018 as the code of practice for protecting PII in public clouds, distinct from the general cloud controls of ISO/IEC 27017. ISO/IEC 27018 targets personally identifiable information handled by public cloud providers acting as PII processors, giving privacy-specific controls. ISO/IEC 27017 covers cloud security controls more broadly, which is why the two are commonly confused, but only 27018 answers the PII-protection requirement.

Why A is correct: ISO/IEC 27018 is the code of practice specifically for protection of personally identifiable information in public clouds that act as PII processors, matching the requirement exactly.

Why B is wrong: ISO/IEC 27017 addresses cloud security controls generally and is easy to confuse here, but it is not the standard focused on protecting PII in public clouds.

Why C is wrong: ISO/IEC 27001 sets out ISMS requirements broadly and is not the PII-in-public-cloud code of practice being sought.

Why D is wrong: NIST SP 800-145 defines cloud computing and its service and deployment models; it says nothing about protecting PII as a processor.

See more CCSP practice questions, answers explained.

More in this domain

Back to all Legal, Risk and Compliance objectives, or the CCSP cert hub.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.