CCSK · Domain 3
Risk, Audit and Compliance
About 12% of the exam
Legal concepts to keep separate
- Data residency
- where the data physically sits
- Data sovereignty
- laws of that country apply
- Data localization
- law forces the data home
- Jurisdiction
- which courts can compel you
- Controller
- decides purpose and means
- Processor
- acts on documented instructions
- Blocking statute
- forbids handing data abroad
- Assistance treaty
- official route between governments
Storage location, processing location and provider nationality can each pull a different legal system into scope
Cross-border transfer
- Adequacy decisions cover some destinations
- Contractual clauses fill the remaining gap
- Transfer impact assessment for onward risk
- Replication silently creates new transfers
- Region pinning is a compliance control
- Encryption reduces but does not remove
Privacy roles
- Data subject
- the person the data describes
- Controller
- accountable to the regulator
- Processor
- the provider under instruction
- Subprocessor
- the provider's own suppliers
- Joint controllers
- shared purpose, shared accountability
- Supervisory authority
- the regulator that enforces
- Breach notification
- the clock starts at awareness
- Rights requests
- access, erasure, portability
Contracts for privacy
- A processing agreement is legally required
- Instructions must be documented
- Subprocessor list and change notice
- Assistance with data subject rights
- Retention and deletion commitments
- Audit and inspection rights
- Breach notification timelines defined
Discovery and evidence requests
- Data is commingled across tenants
- The provider holds the collection capability
- Preserve without altering the metadata
- Legal hold suspends deletion policies
- Produce only the responsive material
- Chain of custody documented throughout
- Native format preserves the evidence
Audit in a multi-tenant world
What you cannot do
- Walk into the data center
- Test the shared fabric freely
- Audit the hypervisor yourself
What you can do
- Read the attestation and its scope
- Review the questionnaire responses
- Audit your own configuration fully
What to check
- Period covered and any exceptions
- Which controls are actually in scope
- Whether answers cite inherited controls
Frameworks and mappings
- The control matrix is the cloud control set
- The questionnaire turns controls into questions
- The registry publishes provider answers
- One control can satisfy several frameworks
- Test once and report many times
- Mapping removes duplicated audit effort
Evidence collection
- Configuration snapshots prove state at a date
- Immutable logs prove the activity happened
- Automated checks give continuous evidence
- Screenshots age badly as evidence
- Provider reports cover inherited controls
- Sampling has to be defensible
Forensics in cloud
- Snapshot the volume before touching it
- Copy into an isolated forensic environment
- Hash the image and record custody
- Volatile memory disappears with the instance
- Provider logs may have short retention
- Agree assistance before an incident happens
Compliance inheritance
- Inherit only what the report covers
- Your configuration is never inherited
- Scope boundaries decide what transfers
- Provider certification is not your certification
- Record the inheritance in the matrix
The audit cycle
- Scope and requirements
- Control mapping
- Evidence collection
- Findings and gaps
- Remediation and retest
Continuous evidence beats an annual scramble, because an automated check produces the artifact at the moment it is true
Legal traps
- Assuming encryption removes jurisdiction
- Ignoring where processing actually happens
- Treating a bridge letter as an audit
- Deleting data under a legal hold
- Missing the breach notification clock
Rapid recall: which document
- Provider control answers
- the assessment questionnaire
- Cloud control framework
- the cloud controls matrix
- Independent period report
- a type two attestation
- Selected controls list
- statement of applicability
- No material change since
- a bridge letter
- Processor obligations
- the data processing agreement
- Government request route
- a legal assistance treaty
- Public assurance listing
- the STAR registry
Reference strip: location, privacy, assurance, audit, investigation
Location law
- Residency is physical location
- Sovereignty is applicable law
- Localization is a legal requirement
- Processing location matters too
Privacy
- Controller and processor roles
- Processing agreement required
- Transfer mechanisms for export
- Clock starts at awareness
Assurance
- Control matrix and questionnaire
- Registry levels and listings
- Period reports and certifications
- Scope and exceptions first
Audit
- No physical inspection rights
- Audit your own configuration
- Continuous evidence over screenshots
- Map once, report many times
Investigation
- Legal hold suspends deletion
- Snapshot then isolate
- Chain of custody recorded
- Short provider log retention
Quick exam traps
- Trap: Encrypting data removes it from a foreign jurisdiction
- Trap: Data residency and data sovereignty are the same requirement
- Trap: A provider certification makes your workload certified
- Trap: You can demand an on-site audit of a public cloud region
- Trap: A bridge letter is an independent audit of the gap period
- Trap: Contractual clauses alone satisfy every cross-border transfer
- Trap: The provider is responsible for answering data subject requests
cybercertprep.com · original revision sheet written from the public body of knowledge