Question 1 of 30
A multinational corporation, \"Aethelred Dynamics,\" has migrated a significant portion of its sensitive research and development data to a public cloud infrastructure. The organization\'s Chief Information Security Officer (CISO) is reviewing the contractual agreements and internal policies to ensure compliance with ISO/IEC 27002:2022 principles regarding cloud service usage. Considering the shared responsibility model inherent in cloud computing, what is the primary and non-delegable security obligation of Aethelred Dynamics as the customer organization in this scenario?
Ensuring the cloud service provider implements robust physical security measures for the data centers hosting their data.
Defining and enforcing the organization's specific security requirements for the cloud service, including access controls and data handling, and monitoring the provider's adherence to these requirements.
Relying solely on the cloud service provider's certifications and audits to validate the overall security posture of the cloud environment.
Assuming that all data processed and stored within the cloud environment is automatically protected by the provider's security framework without any further customer action.

Preparing for ISO/IEC 27002:2022 - Information Security Controls Foundation? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free