Question 1 of 30
A cloud service provider (CSP) operating under ISO 27017:2015 discovers a significant data breach affecting the personal information of multiple customers hosted on its platform. The CSP immediately activates its pre-defined incident response plan, which includes isolating the affected systems, conducting a forensic analysis to determine the scope and cause, and notifying the relevant supervisory authorities and affected customers within the legally mandated timeframe. The plan also outlines steps for remediation and post-incident review to prevent recurrence. Which core principle of ISO 27017:2015 is most directly demonstrated by the CSP\'s actions in this scenario?
Effective information security incident management
Secure development and maintenance of cloud services
Compliance with legal and contractual requirements for data protection
Implementation of robust access control mechanisms

Preparing for ISO 27017:2015 - Cloud Security Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free