CCSK · Domain 2
Cloud Governance and Organization Management
About 14% of the exam
Governance instruments
- Contract
- the primary governance mechanism
- Service level agreement
- measurable target with a remedy
- Responsibility matrix
- who performs which control
- Policy
- the rule the organization sets
- Standard
- the specific way to comply
- Risk register
- record of open and accepted risk
- Assurance report
- evidence a control operates
- Exit clause
- return and deletion of data
In cloud you govern through the contract, because you can no longer govern through physical control of the equipment
Contracts and service levels
- Best efforts is not a target
- Credits rarely cover business loss
- Choice of law decides the venue
- Audit and information rights matter
- Notice periods for material change
- Auto renewal removes your leverage
- Subprocessor notice and objection rights
The responsibility matrix
- One row per control, one owner
- Consulted and informed roles named too
- Shifts between IaaS, PaaS and SaaS
- Gaps get assigned or compensated
- A board artifact, not a diagram
- Reviewed whenever the service changes
Risk management in cloud
- Risk appetite
- how much risk is acceptable
- Risk tolerance
- quantified boundary per risk
- Inherent risk
- before controls are applied
- Residual risk
- what remains after treatment
- Treatment options
- accept, mitigate, transfer, avoid
- Risk owner
- an accountable person, not a team
- Escalation
- beyond tolerance it goes upward
- Concentration risk
- too much on one provider
Supply chain and fourth parties
- Subprocessors inherit your obligations
- Fourth party risk flows through to you
- A new subprocessor triggers reassessment
- Acquisition changes the risk picture
- Invoke audit rights when transparency drops
- Track every service in a register
Assurance you can rely on
The STAR program
- Level one is a self-assessment
- Level two adds third party audit
- Continuous adds ongoing monitoring
- The registry is public and searchable
Other reports
- A period report covers operating effectiveness
- Certification plus statement of applicability
- Government baselines for public sector work
- Regional catalogs for national requirements
Reading them
- Check the period and the scope
- A bridge letter covers the gap
- Exceptions matter more than the opinion
- Inherited controls only within scope
Organization management at scale
Structure
- Hierarchy of accounts or projects
- Separate production from everything else
- Blast radius per business unit
- Naming and tagging agreed centrally
Guardrails
- Central policy applied by inheritance
- Preventive beats detective where possible
- Exceptions time boxed and reviewed
- Break glass paths documented
Consistency
- One control framework across providers
- Unified risk register for multi-cloud
- Landing zone applied to new accounts
- Same severity language everywhere
Vendor selection and exit
- Assess before signing, not after
- Portability designed in at the start
- Data export formats agreed upfront
- Lock-in is a governance risk
- Exit plan tested, not merely written
- Certified deletion on termination
Metrics for the board
- Performance indicator
- how well the control works
- Risk indicator
- forward looking exposure signal
- Reporting cadence
- agreed in advance, kept consistent
- Trend over snapshot
- direction beats a single number
- Coverage metric
- how much estate is governed
- Exception count
- how often policy is bypassed
- Time to remediate
- how quickly findings close
Shadow services and inventory
- Business units buy without registering
- Procurement should feed the inventory
- Discovery tools surface unknown services
- Unknown services carry unassessed risk
- Inventory is the base of governance
- Tie renewal to a reassessment
Governance failures
- Compliance mistaken for governance
- Risk accepted with no named owner
- Assurance report years out of date
- Guardrails present in one provider only
- Exit clause never negotiated
- Matrix written once and forgotten
Know the order
- Set policy
- Assess the provider
- Negotiate the contract
- Assign responsibilities
- Monitor and report
Governance happens before the service goes live, because your leverage disappears the moment the contract is signed
Rapid recall: governance artifacts
- Provider self-assessment
- a questionnaire in the registry
- Independent attestation
- STAR level two
- Operating effectiveness period
- a type two report
- Selected control statement
- statement of applicability
- Who performs each control
- the responsibility matrix
- Quantified acceptable exposure
- risk tolerance
- Forward looking warning
- a key risk indicator
- Data return on exit
- the exit clause
Reference strip: instruments, assurance, risk, organization, lifecycle
Instruments
- Contract and service levels
- Policies and standards
- Responsibility matrix per service
- Risk register with owners
Assurance
- STAR levels through to continuous
- Period reports on effectiveness
- Certification and applicability statement
- Bridge letters cover the gap
Risk
- Appetite, tolerance and treatment
- Inherent against residual
- Concentration and fourth party
- Escalate beyond tolerance
Organization
- Account hierarchy with inheritance
- Guardrails applied centrally
- Landing zone for new accounts
- One framework across providers
Lifecycle
- Assess before you sign
- Monitor while you run
- Reassess on any change
- Exit with certified deletion
Quick exam traps
- Trap: Passing a compliance audit proves the governance program is effective
- Trap: Indemnification transfers regulatory accountability to the provider
- Trap: A large multi-tenant provider will grant you an on-site audit
- Trap: A self-assessed registry listing has been independently verified
- Trap: The service level agreement covers your actual business loss
- Trap: Subprocessors are the provider's problem rather than yours
- Trap: A separate risk register per cloud provider is good practice
cybercertprep.com · original revision sheet written from the public body of knowledge