certslothcertsloth
CCSP/Topic 14

ISC2 / Professional

Cloud Contracts, Privacy and Audit Evidence

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Scope the promise, verify the evidence, plan the exit.

Must remember

Cloud data can cross storage, processing, support and backup jurisdictions. Identify applicable obligations with legal/privacy specialists; do not assume the selected storage region settles every issue. Distinguish ownership, controller, processor, custodian and stewardship responsibilities. A privacy impact assessment considers purpose, necessity, affected people and mitigation.

Contracts should define service boundaries, data use/ownership, security controls, subcontractors, breach notification, audit rights, service levels, evidence access, recovery, return/deletion and termination. An MSA supplies overarching terms; a statement of work defines specific delivery; an SLA defines measurable service commitments and remedies. A credit for downtime may be far smaller than business loss.

Evaluate SOC report type and scope. SOC 1 concerns controls relevant to financial reporting; SOC 2 addresses applicable trust-services criteria; a Type I report considers design at a point in time, whereas Type II includes operating effectiveness over a period. Read exceptions, subservice-organization treatment and complementary customer controls. Do not treat a logo as the report.

Legal holds and discovery requirements may override routine deletion. Negotiate preservation, export formats, access and chain-of-custody assistance before a dispute. Data sanitization in multitenant systems may rely on provider processes and cryptographic techniques; verify contractual assurance rather than demanding physical destruction of shared media indiscriminately.

Risk assessment includes provider viability, concentration, lock-in, supply chains and the organization's ability to operate securely. Insurance, escrow and alternate-provider plans address different consequences and have limitations. Assess an exit plan through tested exports and restoration, not only a termination clause.

Regulatory names are cues to scope, not interchangeable labels. Payment, health, financial and regional privacy obligations differ; certification questions test selecting an appropriate governance process rather than inventing a universal legal rule.

Choose under exam pressure

Requirement Choice and reason
Supplier presents an audit badge Read the actual report scope, period, exceptions and customer duties.
Business depends on one provider Assess concentration and tested recovery/exit options.
Cross-border processing planned Map data flows and obtain the relevant legal/privacy assessment.

Traps

  • An SLA remedy is not necessarily compensation for all damage.
  • A contract cannot simply waive a law that applies to the organization.

Active recall

1. SOC 1 versus SOC 2?

SOC 1 focuses on relevant financial-reporting controls; SOC 2 addresses applicable trust-services criteria.

2. Type I versus Type II?

Point-in-time design versus design and operation over a period.

3. What must an exit clause address beyond cancellation?

Usable data return, keys/access, assistance, deletion evidence and transition timing.

4. Why map subcontractors?

They can introduce additional processing locations, access and contractual dependencies.

5. Who should resolve conflicting jurisdictional obligations?

Qualified legal/privacy owners with the business and security stakeholders.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.