All certifications / CCSP / Cheat sheet
CCSP 2026 outline (effective Aug 1, 2026) cheat sheet
Domain 1: Cloud concepts, architecture & design (17%)
Exam tips
- Know the five NIST characteristics by name. A service that needs a ticket and a week of manual work to add capacity fails on-demand self-service and rapid elasticity, however it is marketed.
- When a question asks who patches the operating system, the answer depends on the model: the customer in IaaS, the provider in PaaS and SaaS. Data and access decisions stay with the customer in all three.
- Hybrid means different deployment models linked together; multi-cloud means more than one provider, which may all be public. Questions often use one word to test whether you confuse it with the other.
- Data, identities and access decisions are always the customer's. If an answer claims the provider is accountable for a customer's data classification or user permissions, it is wrong.
- Containers share a kernel and virtual machines do not; that single fact explains most container-isolation questions. Confidential computing is the answer when the question is about protecting data in use.
- For AI questions, apply the same shared responsibility logic as any other service: the customer still owns its data, access decisions and the business use of the output, whatever the provider manages.
- For sanitization questions in a public cloud, crypto-shredding is usually the best answer because the customer cannot physically destroy shared media.
- RPO drives backup and replication frequency; RTO drives how fast failover must be. If a question gives an acceptable data loss, it is asking about RPO.
- Type I is design at a point in time; Type II is design plus operating effectiveness over a period. When asked which gives the most assurance, pick Type II. Common Criteria rates products, not providers.
Key terms
- Resource pooling
- The provider serves many customers from shared physical resources that are dynamically assigned, with location largely hidden from the customer.
- Rapid elasticity
- The ability to scale capacity up or down quickly, often automatically, so it appears unlimited to the customer.
- Cloud service broker
- A partner that negotiates, integrates or aggregates cloud services from one or more providers on behalf of a customer.
- Multitenancy
- Several customers (tenants) sharing the same infrastructure while their data and workloads are kept logically separated.
- IaaS
- A service model in which the customer rents virtual compute, storage and networking and manages everything from the guest operating system up.
- PaaS
- A service model in which the provider runs the operating system and runtime, and the customer deploys and manages its own applications and data.
- SaaS
- A service model in which the provider delivers a complete application, and the customer manages users, configuration and data.
- Cloud capability type
- ISO/IEC 17788's classification of what a service offers the customer: infrastructure, platform or application capability.
- Community cloud
- A cloud shared by several organizations with common requirements, such as the same regulations, with shared governance and cost.
- Hybrid cloud
- Two or more distinct clouds, such as private and public, bound together so that data and applications can move between them.
- Vendor lock-in
- Dependence on one provider's proprietary services or formats that makes leaving costly or difficult.
- Cloud bursting
- Sending overflow workload from a private environment to public cloud capacity during demand peaks.
- Shared responsibility model
- The division of security duties between cloud provider and customer, which shifts according to the service model.
- Security of the cloud
- The provider's duties: facilities, hardware, host network and virtualization layer.
- Security in the cloud
- The customer's duties: data, identities, configuration and, depending on the model, operating systems and applications.
- Accountability
- Being answerable for the outcome; it stays with the data owner even when tasks are delegated to a provider.
- Container
- A lightweight package of an application and its dependencies that shares the host operating system kernel with other containers.
- Serverless
- A model in which the provider runs code on demand in response to events, and the customer manages no servers.
- Trusted execution environment (TEE)
- A hardware-isolated area of a processor where code and data are protected even from the host operating system and hypervisor.
- Harvest now, decrypt later
- The threat of attackers storing encrypted data today to decrypt it once quantum computers can break current public-key algorithms.
- Large language model (LLM)
- A machine learning model trained on large amounts of text that generates or analyzes language in response to prompts.
- Prompt injection
- An attack in which crafted input causes an AI model to ignore its instructions or perform unintended actions.
- Data poisoning
- Deliberately corrupting training data so that a model learns wrong or malicious behavior.
- Shadow AI
- Use of AI services by staff without the organization's approval or oversight.
- Key management
- The lifecycle of cryptographic keys: generation, distribution, storage, use, rotation, revocation and destruction.
- Crypto-shredding
- Making encrypted data unrecoverable by destroying all copies of the key that encrypted it.
- Management plane
- The console, APIs and tools used to create, configure and delete cloud resources.
- Hypervisor
- Software that creates and runs virtual machines and isolates them from one another.
- Recovery time objective (RTO)
- The maximum acceptable time to restore a service after a disruption.
- Recovery point objective (RPO)
- The maximum acceptable amount of data loss, measured as time before the disruption.
- Business impact analysis (BIA)
- An analysis that identifies critical business processes, the impact of losing them and the recovery objectives they need.
- Security pattern
- A proven, reusable design solution for a recurring security problem.
- ISO/IEC 27017
- A code of practice adding cloud-specific security controls and guidance for providers and customers.
- CSA STAR
- The Cloud Security Alliance's assurance program, with a self-assessment level and a third-party validated level, based on the Cloud Controls Matrix.
- SOC 2 Type II
- An auditor's report on the design and operating effectiveness of a service organization's controls over a period of time.
- FIPS 140-3
- The U.S. standard for validating cryptographic modules, with four increasing security levels.
Domain 2: Cloud data security (20%)
Exam tips
- Classification belongs in the create phase. If a question asks when data should first be classified, choose create, not store or use.
- If a question mentions buckets, metadata and API access, it is object storage. If it mentions data lost at reboot, it is ephemeral storage.
- Tokens have no mathematical link to the original; encrypted values do and can be reversed with the key. If a question stresses reducing compliance scope, tokenization is usually the intended answer.
- DLP needs classification first; it cannot protect data it cannot recognize. When asked what to do before deploying DLP, choose discovering and classifying data.
- BYOK imports the customer's key into the provider; HYOK keeps the key outside the provider. When the question stresses that the provider must never hold the key, choose HYOK or external key management.
- Unstructured data is the hardest to discover and classify because there is no schema to read; content inspection is needed.
- The data owner, not the custodian or IT, decides classification. If an answer has IT or the provider choosing classification levels, it is wrong.
- IRM's distinctive feature is that control continues after the data leaves your systems. If a question asks how to revoke access to a document already sent outside, IRM is the answer, not DLP or storage permissions.
- Legal hold overrides the retention schedule. If a question asks what to do with data under hold whose retention period has ended, the answer is to preserve it.
- Shared accounts destroy accountability. If a question asks how to improve traceability, look for unique identities, synchronized time and protected, centrally stored logs.
- Most AI data protection answers are ordinary data security controls (access control, integrity checks, classification, encryption, logging) applied to training data, models and prompts. Pick the answer that protects integrity when the scenario is poisoning.
Key terms
- Cloud data lifecycle
- The six phases data passes through: create, store, use, share, archive and destroy.
- Data dispersion
- Splitting data into fragments stored in different locations so it can be rebuilt even if some fragments are lost.
- Erasure coding
- A method of adding calculated redundancy to data fragments so the original can be reconstructed from a subset of them.
- Data flow diagram
- A drawing of how data moves between systems, users and parties, showing trust boundaries and processing points.
- Ephemeral storage
- Temporary storage tied to an instance's life that is lost when the instance stops or is terminated.
- Object storage
- Storage that keeps data as objects with metadata in buckets, accessed through APIs rather than a file system.
- Volume storage
- Block storage presented to a virtual machine as a virtual disk that the guest formats with a file system.
- Immutable backup
- A backup copy that cannot be changed or deleted for a set period, protecting it from ransomware and mistakes.
- Tokenization
- Replacing a sensitive value with a random surrogate, with the mapping held in a separate secured vault.
- Dynamic masking
- Hiding or altering data values at query time based on the user's role, without changing the stored data.
- Pseudonymization
- Replacing identifiers with codes that can be re-linked to the person using additional information kept separately.
- Salt
- Random data added to a password before hashing so that identical passwords produce different hashes.
- DLP
- Tools and processes that discover sensitive data, monitor its use and movement, and enforce policies to prevent unauthorized disclosure.
- Exact data matching
- A DLP technique that detects specific records from a known sensitive dataset rather than generic patterns.
- CASB
- A cloud access security broker that sits between users and cloud services to give visibility and enforce security policy, including DLP.
- Data in motion
- Data travelling across a network, such as uploads, email and API calls.
- HSM
- A tamper-resistant hardware device that securely generates, stores and uses cryptographic keys.
- Envelope encryption
- Encrypting data with a data key and then encrypting that data key with a master key held in a key management service.
- BYOK
- Bring your own key: the customer generates keys in its own environment and imports them into the provider's key service.
- HYOK
- Hold your own key: keys stay in the customer's own key service outside the provider and are used remotely when needed.
- Structured data
- Data organized in a defined schema of rows and columns, such as a relational database table.
- Semi-structured data
- Data with tags or keys but no fixed schema, such as JSON, XML or log records.
- Unstructured data
- Data without a predefined model, such as documents, images, audio and free text.
- Data residency
- A requirement that data be stored, and sometimes processed, within a specific geographic location.
- Data classification
- Categorizing data by sensitivity, value and legal requirements to determine how it must be protected.
- Data owner
- The business role accountable for a data set, including deciding its classification and who may access it.
- Data mapping
- Documenting how data elements correspond between systems and where each category of data is stored and flows.
- Data label
- A visible or machine-readable marker that records a data item's classification.
- IRM
- Information rights management: encrypting content and attaching usage policies that are enforced wherever the file goes.
- Persistent protection
- Protection that stays with the data itself regardless of where it is stored or sent.
- Dynamic policy control
- The ability of the owner to change or revoke usage rights after the content has been distributed.
- Automatic expiration
- An IRM feature that stops protected content from being opened after a set date or period.
- Retention period
- The length of time a category of data must be kept to meet legal, regulatory, contractual or business requirements.
- Legal hold
- An instruction to preserve data relevant to anticipated or actual litigation, overriding normal deletion.
- Storage limitation
- The privacy principle that personal data should be kept no longer than necessary for its purpose.
- Archiving
- Moving inactive data to long-term storage where it stays protected and retrievable for its retention period.
- Auditability
- The ability to review a complete, reliable record of events to verify what happened.
- Traceability
- The ability to follow an action or data item through systems back to its origin and actor.
- Non-repudiation
- Assurance that someone cannot credibly deny having performed an action.
- Identity attribution
- Linking each logged action to a specific, unique person or service identity.
- Data provenance
- A record of where data came from and how it has been changed, used to establish trust in it.
- Backdoor (in ML)
- Hidden behavior planted in a model through poisoned training data that activates on a specific trigger.
- Membership inference
- An attack that determines whether a particular record was part of a model's training data.
- Indirect prompt injection
- Malicious instructions hidden in content, such as a web page or document, that an AI system reads and follows.
Domain 3: Cloud platform & infrastructure security (17%)
Exam tips
- The management plane is the highest-value target in the cloud; questions about protecting it point to strong MFA, least privilege, separate administrative identities and logging of every API call.
- Remember the key word for each tier: I basic, II redundant components, III concurrently maintainable, IV fault tolerant.
- When a scenario asks for the most common cause of cloud data exposure, choose misconfiguration by the customer, not an exotic hypervisor attack.
- Physical controls in a public cloud are inherited from the provider; the customer's job is to verify them through audit reports, not to implement them.
- Type 1 runs on bare metal and is used in the cloud; type 2 runs on a host operating system. If a question asks which is more secure for multitenancy, choose type 1.
- Security groups are stateful and attach to instances; NACLs are stateless and attach to subnets. If return traffic is being blocked, suspect a stateless rule missing the outbound direction.
- RTO must be less than or equal to MTD. For exam scenarios, choose the least expensive DR strategy that still meets both the RTO and the RPO, and remember the provider itself can be the disaster.
- Customers cannot tap a provider's physical network. For packet-level visibility in IaaS, the answer is provider traffic mirroring or host-based capture on your own instances; in SaaS, packet capture is generally unavailable.
Key terms
- Availability zone
- One or more physically separate data centers within a region, with independent power, cooling and networking.
- Software-defined networking (SDN)
- Networking in which a software controller manages traffic decisions separately from the hardware that forwards packets.
- Control plane vs data plane
- The control plane decides how traffic or resources are managed; the data plane carries out the actual forwarding or processing.
- Region
- A geographic area containing multiple availability zones operated by a cloud provider.
- Concurrently maintainable
- Tier III property: any component can be removed for planned maintenance without shutting down IT equipment.
- Fault tolerant
- Tier IV property: the facility continues operating through any single unplanned component failure.
- Mantrap
- An entry area with two interlocking doors that allows only one authenticated person through at a time.
- Hot aisle/cold aisle containment
- Arranging server racks so cool intake air and hot exhaust air are kept separate, improving cooling efficiency.
- VM escape
- An attack in which code running inside a virtual machine breaks out to interact with the hypervisor, host or other VMs.
- VM sprawl
- Uncontrolled growth of virtual machines, leaving unmanaged, unpatched systems running.
- Side-channel attack
- An attack that infers secret data from physical effects such as timing, cache behavior or power use rather than from a direct flaw.
- Cloud security posture management (CSPM)
- Tools that continuously check cloud configurations against policies and best practices and report or fix deviations.
- Security control
- A safeguard or countermeasure that avoids, detects, counteracts or reduces a security risk.
- Defense in depth
- Using multiple independent layers of controls so that failure of one does not expose the asset.
- Workload identity
- An identity assigned to an application or service so it can authenticate without stored static credentials.
- Phishing-resistant MFA
- Authentication, such as FIDO2 security keys or passkeys, that cannot be captured and replayed by a fake login page.
- Type 1 hypervisor
- A bare-metal hypervisor that runs directly on hardware, used by cloud providers for its small attack surface.
- Type 2 hypervisor
- A hosted hypervisor that runs as an application on a general-purpose operating system.
- Break-glass account
- An emergency administrative account kept locked away and used only when normal access fails, with every use alerted and reviewed.
- Just-in-time access
- Granting elevated privileges only when needed and for a limited time, rather than permanently.
- Security group
- A stateful virtual firewall attached to an instance or interface that allows specified traffic and automatically permits responses.
- Network ACL
- A usually stateless subnet-level filter with ordered allow and deny rules for inbound and outbound traffic.
- Microsegmentation
- Fine-grained network policy that restricts communication between individual workloads to only what is required.
- Zero trust
- A security model that grants access based on continuous verification of identity and context rather than network location.
- Maximum tolerable downtime (MTD)
- The longest a business process can be unavailable before the organization suffers unacceptable harm.
- Pilot light
- A DR strategy in which core data is replicated and minimal infrastructure is kept ready to scale up during a disaster.
- Warm standby
- A DR strategy in which a scaled-down but functional copy of the environment runs continuously and can be scaled up quickly.
- Tabletop exercise
- A discussion-based test in which participants walk through a scenario and their roles without touching systems.
- SIEM
- Security information and event management: a platform that collects, normalizes, correlates and alerts on logs from many sources.
- Flow log
- A record of network connections showing metadata such as source, destination, ports, protocol and bytes, without packet payloads.
- Traffic mirroring
- A cloud feature that copies network packets from a customer's instance interfaces to a monitoring or analysis destination.
- Correlation
- Linking related events from multiple sources to detect patterns that single events do not reveal.
Domain 4: Cloud application security (16%)
Exam tips
- The CCSP treats training as a preventive control that addresses the root cause. If a question describes the same type of coding flaw recurring across teams, the best long-term answer usually includes developer training, not just another scanner.
- Match the model to the question: STRIDE categorizes threats, DREAD rates them, PASTA is risk-centric and aligned to business objectives, ATASM is a simple architecture-first sequence.
- SSRF is the classic cloud-specific web vulnerability because of instance metadata services. If a scenario involves a server fetching user-supplied URLs and leaking credentials, the answer is SSRF.
- ASVS Level 1 is the minimum for all apps, Level 2 is recommended for apps with sensitive data, and Level 3 is for critical applications. Pick the level that matches the data and business impact in the scenario.
- SAST = code at rest, early, white box. DAST = running app, later, black box. SCA = third-party components. If the question is about a known vulnerable open-source library, SCA is the answer.
- Open source is not automatically risky or safe; the exam favors answers that manage it with inventory (SCA/SBOM), trusted sources, version pinning, signature checks and rapid patching.
- A WAF protects web apps at layer 7 but does not fix vulnerable code; an API gateway handles authentication, quotas and routing for APIs; DAM watches what happens inside the database. Match the tool to where the risk sits.
- OAuth 2.0 is for authorization (delegated access to APIs); OpenID Connect adds authentication on top of it; SAML is the older XML standard for enterprise SSO. Questions often test that OAuth alone does not authenticate users.
Key terms
- Security champion
- A developer or engineer embedded in a team who receives extra security training and promotes secure practices.
- Hard-coded secret
- A password, key or token written directly into source code, configuration or images.
- Insecure default
- A setting that is unsafe out of the box and must be changed to be secure.
- Microservices
- An architecture that splits an application into small, independently deployed services communicating over APIs.
- STRIDE
- A threat classification: spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege.
- DREAD
- A threat scoring model: damage, reproducibility, exploitability, affected users and discoverability.
- PASTA
- Process for Attack Simulation and Threat Analysis, a seven-stage risk-centric threat modeling method.
- Abuse case
- A description of how an attacker might misuse a feature, written alongside normal use cases to drive security requirements.
- OWASP Top 10
- A regularly updated awareness list of the most critical web application security risk categories.
- CWE Top 25
- MITRE's ranked list of the most dangerous specific software weaknesses based on real vulnerability data.
- Server-side request forgery (SSRF)
- A flaw that lets an attacker make a server send requests to destinations of the attacker's choosing, often internal services.
- Broken access control
- A failure to enforce what authenticated users are allowed to do, letting them act outside their permissions.
- ASVS
- The OWASP Application Security Verification Standard, a list of testable security requirements organized into three verification levels.
- Parameterized query
- A database query where user input is passed as separate parameters, so it can never be executed as code.
- Software configuration management
- The discipline of tracking and controlling changes to code, dependencies, build and deployment configuration.
- Output encoding
- Transforming data before display so that the browser treats it as text rather than executable code.
- SAST
- Static application security testing: analyzing code without executing it to find security flaws.
- DAST
- Dynamic application security testing: probing a running application from the outside to find exploitable weaknesses.
- IAST
- Interactive application security testing: an agent inside the running application observes behavior during tests and reports flaws with code context.
- SCA
- Software composition analysis: identifying third-party components and their known vulnerabilities and licenses.
- Software supply chain
- All the components, tools, processes and suppliers involved in building and delivering software.
- Dependency confusion
- An attack where a malicious public package with the same name as an internal one is pulled into a build instead of the real package.
- Artifact signing
- Digitally signing build outputs so consumers can verify they came from the expected source and were not altered.
- Approved API
- An external or internal interface that has been security-reviewed and authorized for use by the organization.
- WAF
- A web application firewall that filters HTTP traffic at layer 7 to block attacks such as injection and cross-site scripting.
- API gateway
- A service that fronts APIs to handle authentication, authorization, rate limiting, routing and logging.
- Database activity monitoring (DAM)
- Monitoring database queries and activity in real time to detect and alert on suspicious or policy-violating access.
- Sandbox
- An isolated, restricted execution environment that contains the effects of untrusted code.
- Identity provider (IdP)
- The system that authenticates users and issues assertions or tokens that other applications trust.
- SAML 2.0
- An XML-based standard for exchanging authentication and attribute assertions between an identity provider and a service provider.
- OpenID Connect
- An identity layer on top of OAuth 2.0 that provides authentication using JSON web tokens.
- CASB
- A cloud access security broker that gives visibility and policy enforcement between users and cloud services.
Domain 5: Cloud security operations (17%)
Exam tips
- TPM is a chip bound to one machine that anchors boot integrity and local keys; an HSM is a dedicated, high-assurance device for managing many keys. Questions about proving boot integrity point to the TPM.
- DNSSEC provides integrity and authenticity of DNS answers, not confidentiality. If the question is about preventing forged DNS responses, choose DNSSEC; if it is about hiding queries, DNSSEC is not the answer.
- Test patches before production, but do not delay critical patches indefinitely. When a patch cannot be applied, the exam expects a documented exception with compensating controls and a remediation date.
- Backups are only proven by successful restores. If an answer choice mentions testing restoration, it is usually stronger than one that only increases backup frequency.
- Incident management restores service fast; problem management finds the root cause. If a question asks which process prevents recurrence, choose problem management.
- Do not shut down a compromised cloud instance first; you would lose volatile evidence. Isolate it, capture memory and snapshot disks, then remediate.
- Communication must follow authority and contracts. In exam scenarios, technical staff should not make public statements on their own; they escalate to the designated communications and legal functions.
- In the incident lifecycle, containment comes before eradication and recovery. In the cloud, the first containment step is often revoking or disabling compromised credentials.
- AI supports, but does not replace, human accountability. In exam scenarios, prefer answers that validate AI output and keep a human approval step for high-impact automated actions.
Key terms
- Trusted platform module (TPM)
- A hardware chip that securely stores keys and boot measurements, supporting secure and measured boot and disk encryption.
- Golden image
- A hardened, pre-approved template used to build consistent, secure instances.
- Measured boot
- Recording measurements of each boot component in the TPM so that the system's startup integrity can be verified.
- Baseboard management controller
- An out-of-band management processor on a server that allows remote control even when the operating system is off.
- Bastion host
- A hardened server that is the only allowed entry point for administrative access to systems in a private network.
- DNSSEC
- DNS Security Extensions, which sign DNS records so resolvers can verify their authenticity and integrity.
- VLAN
- A virtual LAN that logically separates traffic on a shared physical network.
- Privileged access management (PAM)
- Tools and processes that control, broker, record and audit use of privileged accounts.
- Hardening
- Reducing a system's attack surface by removing unnecessary functions and applying secure configuration settings.
- Infrastructure as code (IaC)
- Defining and deploying infrastructure through machine-readable template files kept in version control.
- Configuration drift
- Differences that develop between a system's actual configuration and its approved baseline or code definition.
- Immutable infrastructure
- An approach in which servers are never changed after deployment; updates are made by replacing them with new instances.
- High availability (HA)
- Design that keeps a service running despite component failure, for example by restarting VMs on other hosts in a cluster.
- Maintenance mode
- A host state in which workloads are moved elsewhere so the host can be patched or repaired without downtime.
- Service quota
- A provider-imposed limit on the number or size of resources an account can use.
- 3-2-1 backup rule
- Keep three copies of data on two different media or services, with one copy off-site or isolated.
- Change management
- The process that ensures changes are assessed, approved, tested, implemented and reviewed in a controlled way.
- Problem management
- The process of finding and eliminating the root causes of incidents to prevent recurrence.
- CMDB
- Configuration management database: a repository of configuration items and the relationships between them.
- ISO/IEC 20000-1
- The international standard specifying requirements for an IT service management system.
- Chain of custody
- The documented, unbroken record of who collected, handled, transferred and stored each piece of evidence.
- Order of volatility
- The principle of collecting the most short-lived evidence, such as memory, before more persistent evidence such as disk.
- ISO/IEC 27037
- The international guideline for identifying, collecting, acquiring and preserving digital evidence.
- Forensic image
- An exact, verified bit-for-bit copy of storage media, used for analysis in place of the original.
- Stakeholder
- Any person or organization affected by, or with an interest in, a service or incident.
- Breach notification
- A legally or contractually required notice to regulators or affected individuals after certain data breaches.
- Status page
- A provider's public page reporting current service health, incidents and maintenance.
- Communication plan
- A documented plan stating who communicates what to which stakeholders, when and through which channels.
- SOC
- Security operations center: the team and capability that continuously monitors, detects, investigates and coordinates response to security events.
- SOAR
- Security orchestration, automation and response: tools that automate and coordinate incident response steps through playbooks.
- Alert fatigue
- Desensitization caused by too many alerts, especially false positives, leading analysts to miss real threats.
- Authenticated scan
- A vulnerability scan that logs in to systems to inspect installed software and configuration in detail.
- Anomaly detection
- Identifying events that deviate significantly from a learned baseline of normal behavior.
- UEBA
- User and entity behavior analytics: analysis of the behavior of users, devices and service accounts to detect threats.
- False negative
- A real malicious event that a detection system fails to flag.
- Human in the loop
- A design in which a person reviews or approves decisions before an automated system acts on them.
Domain 6: Legal, risk & compliance (13%)
Exam tips
- When a question involves data in several countries, think about the strictest applicable law and about where the provider is headquartered, not only where the data center is.
- The customer is normally the controller and the cloud provider the processor. Outsourcing processing never transfers the controller's accountability.
- SOC 1 is about financial reporting controls; SOC 2 is about security and the other trust services criteria; SOC 3 is the public summary. For cloud security due diligence, a SOC 2 Type II report is usually the right evidence.
- Insurance and contracts can transfer financial loss, but accountability stays with the data owner. If an answer claims the provider becomes accountable for the customer's data, it is wrong.
- ISO/IEC 31000 is general risk management guidance and is not certifiable; NIST SP 800-37 is the system-level RMF behind FedRAMP; ENISA's work catalogs cloud-specific risks. Match the framework to the purpose in the question.
- Service credits compensate for missed SLAs but rarely cover the real business loss. When an exam question asks how to protect against lock-in, look for exit and data portability terms in the contract.
- Policy comes first and is high level; standards and procedures implement it. When a question asks what should be in place before approving cloud services across the organization, a cloud policy approved by management is usually the answer.
- Using a provider's AI service does not transfer accountability for decisions made with it. For AI ethics questions, favor answers with human oversight, bias testing, transparency to affected people and a named accountable owner.
- A provider's certification covers only the listed services and the provider's own responsibilities. If a question asks what the customer must verify, choose confirming that the specific services used are in scope and that the customer's own controls are compliant.
Key terms
- Jurisdiction
- The legal authority of a court or government over people, organizations and data within a territory.
- eDiscovery
- The identification, preservation, collection, review and production of electronically stored information for legal matters.
- ISO/IEC 27050
- The international standard series providing guidance on electronic discovery.
- Data localization
- A legal requirement that certain data be stored or processed within a specific country.
- Data controller
- The party that determines the purposes and means of processing personal data and is accountable for it.
- Data processor
- A party that processes personal data on behalf of the controller, such as a cloud provider.
- Business associate agreement (BAA)
- A HIPAA-required contract under which a service provider agrees to protect PHI it handles for a covered entity.
- Privacy impact assessment (PIA)
- An assessment of how a project collects, uses and protects personal data and what privacy risks it creates.
- Right to audit
- A contract clause allowing the customer, or its auditor, to audit the provider's controls.
- SOC 3
- A general-use summary report on a service organization's controls against the trust services criteria, without detailed test results.
- Complementary user entity controls (CUECs)
- Controls a customer must implement for the provider's controls described in a SOC report to be effective.
- Gap analysis
- A comparison of current controls with a target standard to identify what is missing or inadequate.
- Enterprise risk management (ERM)
- An organization-wide approach to identifying, assessing and treating risks in line with business objectives.
- Risk appetite
- The amount and type of risk an organization is willing to accept in pursuit of its objectives.
- Residual risk
- The risk that remains after controls and other treatments have been applied.
- Risk transfer
- Shifting the financial consequences of a risk to another party, for example through insurance or contract terms.
- ISO/IEC 31000
- An international standard giving principles and guidelines for risk management applicable to any organization.
- NIST Risk Management Framework
- The seven-step lifecycle in NIST SP 800-37: prepare, categorize, select, implement, assess, authorize and monitor.
- Key risk indicator (KRI)
- A metric that signals increasing exposure to a risk, used as an early warning.
- ENISA cloud risk assessment
- ENISA's analysis of cloud-specific risks across policy and organizational, technical and legal categories.
- Service level agreement (SLA)
- A contract component defining measurable service commitments and remedies if they are not met.
- Master services agreement (MSA)
- The overarching contract setting the legal terms that govern all work between the parties.
- Statement of work (SOW)
- A document describing specific services, deliverables, schedule and costs under the MSA.
- ISO/IEC 27036
- The international standard series on information security in supplier relationships, including cloud services.
- Organizational policy
- A high-level, management-approved statement of intent that applies across the whole organization.
- Functional policy
- A policy governing a specific security area, such as access control or incident response.
- Guardrail
- An automated organization-wide control that prevents or detects actions that violate policy in cloud accounts.
- Policy exception
- A documented, approved and time-limited deviation from a policy, with the associated risk accepted by the right authority.
- EU AI Act
- The European Union's risk-based regulation of artificial intelligence systems, with obligations that increase with risk.
- Algorithmic bias
- Systematic and unfair differences in an AI system's outcomes for particular groups of people.
- Explainability
- The ability to describe in understandable terms how an AI system reached a particular output or decision.
- ISO/IEC 42001
- An international standard specifying requirements for an AI management system.
- PCI DSS
- The Payment Card Industry Data Security Standard, which sets security requirements for entities handling cardholder data.
- FedRAMP
- The US government program that standardizes security assessment, authorization and continuous monitoring of cloud services for federal use.
- NERC CIP
- North American Electric Reliability Corporation Critical Infrastructure Protection standards for the bulk electric system.
- Responsibility matrix
- A provider document mapping each compliance requirement to the provider, the customer or both.
Study CCSP for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the CCSP study planLessons, quizzes, exam simulations and hands-on labs.