Question 1 of 30
A global financial institution, \"Aethelred Capital,\" is migrating its customer transaction data to a cloud environment, opting for a managed Platform as a Service (PaaS) database offering from \"NebulaCloud Services.\" Aethelred Capital\'s internal audit team, preparing for an ISO 27017:2015 compliance audit, is scrutinizing the control implementation for sensitive customer data residing in this PaaS database. Given that NebulaCloud Services is responsible for the underlying infrastructure, operating system patching, and database software maintenance as per their service agreement, what specific area of security control implementation remains a primary obligation for Aethelred Capital to demonstrate compliance with ISO 27017:2015, particularly concerning data protection and access management within the managed database?
Implementing granular access control policies for data within the database and ensuring appropriate data classification and handling procedures are followed.
Regularly patching the underlying server operating system to protect against known vulnerabilities.
Managing the physical security of the data centers where the database instances are hosted.
Performing vulnerability scans on the network interfaces exposed by NebulaCloud Services to the public internet.

Preparing for ISO 27017:2015 Lead Implementer? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free