Question 1 of 30
Considering the shared responsibility model inherent in cloud computing as delineated by ISO 27017:2015, which of the following best describes the primary responsibility of a Cloud Service Provider (CSP) concerning the establishment of foundational security policies when offering Infrastructure as a Service (IaaS)?
The CSP is primarily responsible for establishing and maintaining information security policies that govern the security of the cloud service itself, including the underlying infrastructure and the security of data processed by the service.
The CSC is primarily responsible for establishing information security policies that dictate the acceptable use of the cloud service and the security of data uploaded by its users.
Both the CSP and the CSC share equal and direct responsibility for defining the security policies related to the physical security of the data centers hosting the cloud infrastructure.
The CSP's responsibility is limited to providing a secure platform, with all policy-related security decisions solely resting with the Cloud Service Customer (CSC).

Preparing for ISO 27017:2015 - Cloud Services Security Controls Professional? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free