CCSK Exam QuestionsBrowse all questions from this exam

CCSK Exam - Question 84


For third-party audits or attestations, what is critical for providers to publish and customers to evaluate?

Show Answer
Correct Answer: AC

For third-party audits or attestations, it is critical for providers to publish the scope of the assessment and the exact included features and services for the assessment. This allows customers to understand what was evaluated and ensure it aligns with their specific security, compliance, and regulatory requirements. Transparency in the assessment's scope helps customers make informed decisions about the security and reliability of the provider's offerings.

Discussion

6 comments
Sign in to comment
beazzlebubOption: A
Oct 8, 2022

From Security Guidance v4. Section 3.1.2.5: It is critical for a provider to publish, and a customer to evaluate, the scope of the assessment, and which features and services are included in the assessment.

cjkugaOption: A
Oct 30, 2022

Agree with beazzlebub's answer

A_NevermindOption: A
Nov 29, 2022

It is A

negevonOption: A
Aug 6, 2023

its clearly A

SKUNK1
Feb 9, 2023

Agree with beazzlebub too

BrainiacOption: A
May 28, 2023

For third-party audits or attestations, it is critical for providers to publish and customers to evaluate: A. Scope of the assessment and the exact included features and services for the assessment. When it comes to third-party audits or attestations, the scope of the assessment is of utmost importance. Providers should clearly publish the scope of the assessment, specifying the exact features, services, and components included in the assessment. This helps customers understand which aspects of the provider's offering have been evaluated for security, compliance, or other relevant factors. By evaluating the scope, customers can assess if the assessed components align with their specific requirements, regulatory obligations, or industry standards. It provides transparency and allows customers to make informed decisions regarding the security and compliance of the provider's offerings.