Career Employer

Your FREE CCSP Flashcards 2026 – 200+ Cards

Realistic, CCSP exam-style flashcards across all 6 ISC2 cloud security domains — flip, match, type, and quiz yourself.

How well do you know them?

To find us again, just search “Career Employer CCSP”

By

Click Study Flashcards above to open the flashcard hub — hundreds of CCSP cards you can flip, match, type, or quiz yourself on. Every card is drawn from the six official ISC2 domains, so you study exactly what the exam tests.[1] Pair them with our free practice test and study guide.

CCSP is one of the 9 ISC2 certifications — explore our ISC2 flashcards to compare and prep across the whole family.

CCSP Flashcard Study Modes

Flip mode lets you study one card at a time and check yourself, Match turns term-to-definition recall into a timed game, Type asks you to read a definition and type the term back, and Quiz builds multiple choice from the same 245 cards. Type is where a front like BYOK stops being familiar and starts being something you can actually produce.

Free CCSP flashcards from Career Employer — active recall for the Certified Cloud Security Professional exam

Why Flashcards Work for the CCSP

Cloud Data Security carries the largest share at 20% and the largest stack at 50 cards. These drill the protection and lifecycle vocabulary you need on sight: cryptography terms such as AES and TLS, key custody distinctions like BYOK and HYOK, and data-control terms including DLP and IRM. Lifecycle cards such as Use phase and technique cards like Hashing sit alongside them.

Cloud Concepts, Architecture & Design holds 45 cards and 17%. The fronts cover service models, so PaaS, SaaS, and IaaS all appear separately, plus assurance and framework shorthand such as CSA CCM, CSA STAR, and CAIQ. Architectural terms like Container and Zero trust round out the foundation the rest of the deck builds on.

Cloud Application Security also sits at 17%, with 43 cards split between testing and identity. Code and traffic defense shows up as SAST, SCA, and WAF, while access control terms cluster around IAM, SSO, and MFA. Supporting cards such as PKI and DAM fill in the monitoring and trust pieces.

Cloud Platform & Infrastructure Security has 31 cards for another 17%, weighted toward resilience and virtualization risk. Recovery metrics dominate, with RTO, RPO, and RSL as separate fronts plus a comparison card, RTO vs RPO. Continuity terms like BCDR and Failover pair with virtualization threats such as VM escape and VM sprawl.

Cloud Security Operations brings 34 cards and 16%, covering operational tooling and forensic standards: SIEM, ITIL, and Honeypot, plus standard references like ISO/IEC 27037 and ISO/IEC 27050 alongside Log management. Legal, Risk & Compliance adds 42 cards at 13%, drilling privacy and audit language including PII, GDPR, and GAPP, contract terms such as SLA, and the audit report family SOC 1, SOC 2, and SOC 3.

The CCSP is dense with terminology — the data lifecycle, encryption and key management, virtualization, cloud IAM, standards, and compliance frameworks.[3] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.

CCSP Flashcards by Domain

The cards are organized by the six official ISC2 domains. Cover them all, but start with the largest, Cloud Data Security:[1]

CCSP flashcards by domain and weight
DomainExam weight
Cloud Data Security20%
Cloud Concepts, Architecture & Design17%
Cloud Platform & Infrastructure Security17%
Cloud Application Security17%
Cloud Security Operations16%
Legal, Risk & Compliance13%

How to Get the Most Out of These Flashcards

  • Start with the heaviest stack. Cloud Data Security is 50 cards and 20% of the exam, so run it in Flip first until the encryption and key custody fronts feel automatic.
  • Type the near-twins. Use Type mode on pairs that blur together, especially BYOK and HYOK, and on recovery metrics where RTO vs RPO decides the answer.
  • Match the acronym families. Match is ideal for the audit and framework shorthand — SOC 1, SOC 2, and SOC 3, plus CSA CCM and CSA STAR — where speed matters more than depth.
  • Move on when Quiz stops surprising you. Once a domain returns clean Quiz rounds twice in a row, shift to the practice test and let scenario questions expose the gaps flashcards cannot.
  • Rotate rather than binge. With 245 cards across six domains, work one domain per sitting, then re-flip yesterday’s domain briefly before starting the next, and read the study guide for anything you keep missing.

CCSP Flashcards FAQ

Hundreds of free CCSP flashcards, organized across all six ISC2 domains — Cloud Concepts, Architecture & Design; Cloud Data Security; Cloud Platform & Infrastructure Security; Cloud Application Security; Cloud Security Operations; and Legal, Risk & Compliance. They're free with no account required.

CCSP flashcard bank

All 245 cards, by topic

A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.

Cloud Concepts, Architecture & Design (45)

Shared responsibility model
Show answer

Security duties split between cloud provider and customer; the boundary shifts by service model, but data and access are always the customer's.

Cloud computing (NIST definition)
Show answer

On-demand network access to a shared pool of configurable computing resources, rapidly provisioned and released with minimal management effort (NIST SP 800-145).

Five essential characteristics of cloud
Show answer

On-demand self-service, broad network access, resource pooling, rapid elasticity, measured service.

On-demand self-service
Show answer

A consumer can provision computing capabilities automatically, without human interaction with the provider.

Broad network access
Show answer

Capabilities are available over the network and accessed through standard mechanisms across diverse client devices.

Resource pooling
Show answer

Provider resources are pooled to serve multiple consumers in a multi-tenant model, dynamically assigned and reassigned.

Rapid elasticity
Show answer

Capabilities scale out and in quickly, appearing unlimited to the consumer and matching demand.

Measured service
Show answer

Resource usage is metered and reported, enabling pay-per-use billing and optimization.

IaaS
Show answer

Infrastructure as a Service — provider supplies compute, storage, and networking; customer manages the OS, runtime, and applications.

PaaS
Show answer

Platform as a Service — provider supplies a managed platform/runtime; customer manages only the deployed application and its data.

SaaS
Show answer

Software as a Service — provider delivers a fully managed application; customer manages only data and limited settings.

Who secures most in IaaS vs SaaS?
Show answer

The customer secures the most in IaaS and the least in SaaS; the provider's share grows from IaaS to SaaS.

Always the customer's responsibility
Show answer

Data classification and access management (IAM) — in every service model, regardless of provider.

Always the provider's responsibility
Show answer

The physical infrastructure and the virtualization/hypervisor layer — in every service model.

Public cloud
Show answer

Cloud infrastructure provisioned for open use by the general public.

Private cloud
Show answer

Cloud infrastructure provisioned for the exclusive use of a single organization.

Community cloud
Show answer

Cloud infrastructure shared by several organizations with common concerns (mission, security, compliance).

Hybrid cloud
Show answer

A composition of two or more distinct clouds bound by technology enabling data and application portability.

Multi-cloud
Show answer

Using cloud services from more than one provider, often to avoid lock-in or improve resilience.

Cloud service provider (CSP)
Show answer

The entity that offers and operates cloud services.

Cloud service customer (CSC)
Show answer

The entity that consumes cloud services.

Cloud broker
Show answer

An intermediary that manages the use, performance, and delivery of cloud services and negotiates relationships.

Cloud reference architecture
Show answer

A conceptual model describing cloud roles, activities, and functions (NIST SP 500-292).

Virtualization
Show answer

Abstracting physical resources into virtual instances so one host can run many isolated workloads.

Container
Show answer

OS-level virtualization packaging an app with its dependencies; shares the host kernel — lighter than a VM.

Microservices
Show answer

An architecture that decomposes an application into small, independently deployable services.

Serverless / FaaS
Show answer

An execution model where the provider fully manages infrastructure and code runs in response to events.

Microsegmentation
Show answer

Fine-grained network isolation policies down to individual workloads; a building block of zero trust.

Confidential computing
Show answer

Protecting data in use by processing it inside a hardware-based trusted execution environment (TEE).

Edge computing
Show answer

Processing data near where it is generated to reduce latency and bandwidth use.

Zero trust
Show answer

A model granting no implicit trust by network location; every request is authenticated, authorized, and continuously validated.

Cloud secure design principles
Show answer

Build on the data lifecycle, BCDR planning, cost-benefit analysis, functional security requirements, and zero trust.

Common Criteria (ISO/IEC 15408)
Show answer

An international standard for evaluating the security assurance of a product or system.

FIPS 140-3
Show answer

The current U.S. federal standard for validating cryptographic modules (succeeding FIPS 140-2).

CSA STAR
Show answer

CSA's Security, Trust, Assurance and Risk registry — provider self-assessment (CAIQ) and third-party certification.

CSA CCM
Show answer

Cloud Controls Matrix — a vendor-neutral cloud security control framework mapped to major standards.

CAIQ
Show answer

Consensus Assessments Initiative Questionnaire — a CSP self-assessment aligned to the CSA CCM.

Evaluating a cloud provider
Show answer

Verify against criteria such as ISO/IEC 27017, Common Criteria, and FIPS 140-3, plus SOC 2 and CSA STAR.

Tenancy isolation
Show answer

Keeping one tenant's data and workloads separated from others in a multi-tenant cloud — a core security goal.

Vendor (cloud) interoperability
Show answer

The ability of cloud systems to work together and exchange data, reducing lock-in.

Portability (cloud)
Show answer

The ability to move data and applications between providers without major rework.

Reversibility (cloud)
Show answer

A customer's ability to retrieve data and terminate a service so the provider can no longer access it.

Defense in depth
Show answer

Layering multiple, overlapping controls so one failure doesn't expose the asset.

Multi-tenancy
Show answer

Many customers sharing the same physical resources with logical isolation between them.

Service model and responsibility
Show answer

More control (IaaS) means more security responsibility; more convenience (SaaS) means less.

Cloud Data Security (50)

Cloud secure data lifecycle
Show answer

Six phases: Create, Store, Use, Share, Archive, Destroy.

Create phase
Show answer

Data is generated or modified; classify and label it as early as possible.

Store phase
Show answer

Data committed to storage; apply encryption at rest and access controls.

Use phase
Show answer

Data viewed or processed; enforce least privilege and information rights management.

Share phase
Show answer

Data made available to others; control egress with DLP and protect transit with TLS.

Archive phase
Show answer

Data moved to long-term retention; apply retention policy, encryption, and integrity checks.

Destroy phase (cloud)
Show answer

Permanent removal; in the cloud this means crypto-shredding (destroying the keys).

Volume storage
Show answer

Block storage attached to a VM like a virtual hard disk (IaaS).

Object storage
Show answer

Storage of data as objects with metadata, accessed via API (e.g., buckets).

Ephemeral storage
Show answer

Temporary storage tied to a running instance; lost when the instance stops.

Structured vs unstructured data
Show answer

Structured fits a defined schema (databases); unstructured does not (documents, media).

Encryption
Show answer

Transforming plaintext into ciphertext with an algorithm and key; reversible only with the key.

Encryption at rest
Show answer

Protecting stored data so it is unreadable without the key.

Encryption in transit
Show answer

Protecting data moving across networks, typically with TLS.

Encryption in use
Show answer

Protecting data while processed, via confidential computing / trusted execution environments.

Key management system (KMS)
Show answer

A system that generates, stores, rotates, and retires cryptographic keys.

BYOK
Show answer

Bring Your Own Key — the customer generates or imports keys into the provider's KMS.

HYOK
Show answer

Hold Your Own Key — the customer keeps and controls keys entirely outside the provider's environment.

Key escrow
Show answer

Storing a copy of keys with a trusted third party for recovery or lawful access.

Tokenization
Show answer

Replacing sensitive data with a non-sensitive token mapped to the real value in a separate secure vault.

Tokenization vs encryption
Show answer

Tokenization swaps data for a vault-mapped token (no key on the data); encryption transforms data with a key.

Data masking
Show answer

Substituting or scrambling data while preserving its format, typically for test/dev use.

Anonymization
Show answer

Irreversibly removing identifiers so data can never be re-linked to an individual.

Pseudonymization
Show answer

Replacing identifiers with pseudonyms that can be re-linked only with separate, protected information.

Data obfuscation
Show answer

Umbrella term for hiding sensitive data (masking, anonymization, tokenization).

Data dispersion
Show answer

Splitting data into fragments stored across locations (cloud RAID-like) for resilience.

Bit splitting
Show answer

Dividing encrypted data into segments distributed across storage so no node holds usable data.

Crypto-shredding
Show answer

Cryptographic erasure — making data unrecoverable by destroying its encryption keys.

Data remanence (cloud problem)
Show answer

Residual data that may persist on shared media you cannot physically wipe — solved by crypto-shredding.

DLP
Show answer

Data Loss Prevention — discover, monitor, and block unauthorized exfiltration of sensitive data.

DLP three stages
Show answer

Discovery, monitoring, and enforcement.

Data discovery
Show answer

Finding and locating sensitive data across structured, unstructured, and semi-structured stores.

Data classification
Show answer

Categorizing data by sensitivity so the right protection, retention, and destruction rules apply.

Data labeling
Show answer

Tagging data with classification and handling metadata.

IRM
Show answer

Information Rights Management — persistent access and usage controls bound to a data object wherever it travels.

Data retention policy
Show answer

Rules for how long data must be kept before deletion or archiving.

Legal hold
Show answer

Suspending normal deletion to preserve data relevant to litigation or investigation.

Auditability of data events
Show answer

Logging data events to provide traceability, accountability, and nonrepudiation.

Chain of custody
Show answer

Documented handling of evidence that preserves its integrity and legal admissibility.

Nonrepudiation
Show answer

Assurance that an actor cannot deny having performed an action.

Hashing
Show answer

A one-way function producing a fixed-length digest used to verify integrity.

Data sovereignty
Show answer

The principle that data is subject to the laws of the country where it is stored.

Data residency
Show answer

The physical or geographic location where data is stored.

Symmetric encryption
Show answer

Uses one shared secret key for both encryption and decryption (e.g., AES); fast.

Asymmetric encryption
Show answer

Uses a public/private key pair (e.g., RSA, ECC); solves key exchange and enables signatures.

AES
Show answer

Advanced Encryption Standard — the dominant symmetric block cipher used for cloud data at rest.

TLS
Show answer

Transport Layer Security — the protocol that protects data in transit (HTTPS).

Data flow mapping
Show answer

Documenting how data moves through systems to find where to apply controls.

Tokenization use case
Show answer

Common for payment card (PAN) data because the token carries no exploitable value if stolen.

Encryption key rotation
Show answer

Periodically replacing keys to limit exposure if a key is compromised.

Cloud Platform & Infrastructure Security (31)

Cloud infrastructure components
Show answer

Physical environment, network and communications, compute, virtualization, storage, and the management plane.

Management plane
Show answer

The centralized console/API to provision and control cloud resources — the highest-value target.

Why protect the management plane
Show answer

Compromising it can give an attacker control of the entire cloud environment at once.

Hypervisor
Show answer

Software that creates and runs virtual machines, allocating host resources to guests.

Type 1 hypervisor
Show answer

Bare-metal — runs directly on hardware, no host OS; smaller attack surface; used in production cloud.

Type 2 hypervisor
Show answer

Hosted — runs atop a host OS; larger attack surface; used for desktop labs.

More secure hypervisor type
Show answer

Type 1 (bare-metal), because there is no host OS to compromise.

VM escape
Show answer

An attack where a guest VM breaks isolation to reach the hypervisor or host, threatening other tenants.

VM sprawl
Show answer

Uncontrolled growth of virtual machines, increasing attack surface and management burden.

Container security risk
Show answer

Containers share the host kernel, so a kernel compromise can affect all containers on the host.

Compute security
Show answer

Securing the processing resources (CPU/memory) allocated to workloads.

Storage security (infrastructure)
Show answer

Protecting the storage layer with encryption, access control, and isolation.

Network security (cloud)
Show answer

Securing communications with segmentation, firewalls, and encryption in transit.

Data center tiers
Show answer

Uptime Institute Tiers I–IV rate data-center redundancy and availability (IV = highest).

HVAC in data center design
Show answer

Heating, ventilation, and air conditioning maintain environmental conditions for reliability.

Logical vs physical design
Show answer

Logical design defines structure/relationships; physical design defines actual hardware and layout.

Risk assessment (infrastructure)
Show answer

Identify, analyze, and mitigate cloud-specific threats, vulnerabilities, and attacks.

Security controls (cloud platform)
Show answer

Physical/environmental, system/communication, virtualization protection, IAM, and audit mechanisms.

Audit mechanisms (infrastructure)
Show answer

Log collection, log correlation, and packet capture for monitoring and investigation.

BCDR
Show answer

Business Continuity and Disaster Recovery — plans to maintain and restore operations after a disruption.

RTO
Show answer

Recovery Time Objective — the maximum acceptable time to restore a process after a disruption.

RPO
Show answer

Recovery Point Objective — the maximum acceptable data loss measured backward in time; drives backup frequency.

RSL
Show answer

Recovery Service Level — the percentage of full compute capacity a process needs during a disaster.

RTO vs RPO
Show answer

RTO = time to recover; RPO = how much data you can afford to lose.

BCDR strategy steps
Show answer

Define business requirements, create the strategy, implement it, and test it.

High availability (HA)
Show answer

Designing systems to remain operational despite component failures.

Clustering
Show answer

Linking servers so they act as one system for availability and load distribution.

Redundancy
Show answer

Duplicating components so a failure does not cause an outage.

Failover
Show answer

Automatically switching to a standby system when the primary fails.

Cloud bursting
Show answer

Using public cloud capacity to handle demand spikes beyond a private cloud's capacity.

Tenant isolation failure
Show answer

A breakdown in separation that lets one tenant access another's data or workloads.

Cloud Application Security (43)

Secure SDLC
Show answer

Building security into every phase of software development rather than testing for it at the end.

Secure SDLC phases
Show answer

Requirements/training, design, develop, test, deploy, operate/maintain.

Threat modeling
Show answer

Systematically identifying and prioritizing threats to a system during design.

STRIDE
Show answer

Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege.

DREAD
Show answer

A risk-rating model: Damage, Reproducibility, Exploitability, Affected users, Discoverability.

PASTA
Show answer

Process for Attack Simulation and Threat Analysis — a risk-centric threat-modeling methodology.

SAST
Show answer

Static Application Security Testing — analyzing source or binary code without executing it.

DAST
Show answer

Dynamic Application Security Testing — testing a running application from the outside.

IAST
Show answer

Interactive AST — instrumenting a running app to combine static and dynamic analysis.

SCA
Show answer

Software Composition Analysis — identifying open-source components and their known vulnerabilities.

SAST vs DAST
Show answer

SAST inspects code early; DAST tests the running app for runtime/config flaws.

OWASP Top 10
Show answer

A community list of the most critical web application security risks.

SANS Top 25
Show answer

A list of the most dangerous software errors (CWE).

Input validation
Show answer

Checking and sanitizing all input to prevent injection and other attacks — never trust user input.

SQL injection
Show answer

Inserting malicious SQL via unvalidated input to read or alter a database.

OWASP ASVS
Show answer

Application Security Verification Standard — a framework of security requirements for testing apps.

Software supply-chain security
Show answer

Securing third-party, open-source, and vendor components and their provenance.

Verified secure software
Show answer

Using approved, validated APIs and components from trusted sources.

Sandboxing
Show answer

Isolating execution so untrusted code cannot affect the wider system.

Application virtualization
Show answer

Running an application in an isolated environment abstracted from the OS.

Orchestration
Show answer

Automating the deployment, scaling, and management of containers/workloads (e.g., Kubernetes).

WAF
Show answer

Web Application Firewall — filters and monitors HTTP traffic to protect web applications.

API gateway
Show answer

A managed entry point enforcing authentication, rate limiting, and routing for APIs.

DAM
Show answer

Database Activity Monitoring — real-time monitoring of database transactions.

XML firewall
Show answer

A device/service that inspects and filters XML traffic to protect web services.

IAM
Show answer

Identity and Access Management — the framework for managing digital identities and access rights.

Federated identity
Show answer

Linking a user's identity across multiple systems or organizations.

Identity provider (IdP)
Show answer

A service that authenticates users and issues identity assertions to relying parties.

SSO
Show answer

Single Sign-On — one authentication grants access to multiple systems.

MFA
Show answer

Multi-Factor Authentication — verifying identity with two or more independent factors.

SAML
Show answer

An XML-based standard for federated authentication and web single sign-on.

OAuth 2.0
Show answer

An authorization framework granting an app delegated access to resources without sharing credentials.

OpenID Connect (OIDC)
Show answer

An authentication layer built on OAuth 2.0 that adds identity (who the user is).

SAML vs OAuth vs OIDC
Show answer

SAML and OIDC handle authentication; OAuth 2.0 alone handles authorization (delegated access).

CASB
Show answer

Cloud Access Security Broker — a policy enforcement point giving visibility, compliance, data security, and threat protection.

CASB four pillars
Show answer

Visibility, compliance, data security, and threat protection.

Secrets management
Show answer

Securely storing and controlling access to credentials, keys, and tokens used by applications.

Cryptographic agility
Show answer

Designing systems so cryptographic algorithms can be swapped without major rework.

PKI
Show answer

Public Key Infrastructure — the framework of certificate authorities and certificates that manages public keys.

Digital signature
Show answer

A hash encrypted with the signer's private key, providing integrity, authenticity, and nonrepudiation.

Least privilege
Show answer

Granting only the minimum access needed to perform a task, and nothing more.

Separation of duties
Show answer

Splitting a sensitive task so no single person can complete it alone.

Abuse-case testing
Show answer

Testing how an application behaves under intentional misuse, not just normal use.

Cloud Security Operations (34)

BIOS/UEFI hardening
Show answer

Securing firmware settings to reduce the attack surface of a host before the OS loads.

TPM
Show answer

Trusted Platform Module — a hardware chip that stores keys and supports host attestation.

Host attestation
Show answer

Verifying the integrity and trust state of a host before extending trust to it.

OS hardening (baselines)
Show answer

Configuring an OS to a secure baseline by removing unneeded services and applying secure settings.

Patch management
Show answer

Identifying, testing, and applying updates to fix vulnerabilities promptly.

Infrastructure as code (IaC)
Show answer

Defining and provisioning infrastructure through machine-readable config files for consistency.

Jumpbox (bastion host)
Show answer

A hardened intermediary host used to access systems in a protected network.

Secure shell (SSH)
Show answer

An encrypted protocol for secure remote administration.

RDP
Show answer

Remote Desktop Protocol — remote GUI access that must be secured (MFA, restricted exposure).

Scalability (operations)
Show answer

The ability to grow or shrink capacity to meet demand while remaining available.

ITIL
Show answer

A framework of IT service management best practices used to run cloud operations.

ISO/IEC 20000-1
Show answer

The international standard for an IT service management system.

Change management
Show answer

Evaluating, approving, and documenting changes — prevents most cloud incidents.

Configuration management
Show answer

Tracking the state and relationships of assets across the environment.

Release & deployment management
Show answer

Controlling repeatable, low-risk rollouts of changes.

Problem management
Show answer

Identifying and eliminating the root causes of recurring incidents.

Incident management
Show answer

Detecting, responding to, and recovering from security/operational events.

Service-level management
Show answer

Defining, meeting, and reporting on service-level agreements (SLAs).

Availability management
Show answer

Ensuring services meet agreed availability targets.

Capacity management
Show answer

Ensuring sufficient resources to meet current and future demand.

SOC (Security Operations Center)
Show answer

The team and function that monitors and responds to security events.

SIEM
Show answer

Security Information and Event Management — aggregates and correlates logs for detection and investigation.

Log management
Show answer

Collecting, retaining, and protecting logs to support detection and forensics.

Digital forensics (cloud)
Show answer

Collecting and analyzing evidence in the cloud, where you don't control the physical media.

ISO/IEC 27037
Show answer

Guidelines for identification, collection, acquisition, and preservation of digital evidence.

ISO/IEC 27050
Show answer

Standard for electronic discovery (eDiscovery).

Evidence management
Show answer

Handling evidence to preserve integrity and an unbroken chain of custody.

Vulnerability assessment
Show answer

Scanning systems to identify and prioritize known weaknesses.

Communication with relevant parties
Show answer

Coordinating with vendors, customers, partners, regulators, and stakeholders during operations and incidents.

Cloud forensics challenge
Show answer

Multi-tenancy, data location, and provider dependence make evidence collection complex.

Baseline (security)
Show answer

A documented minimum secure configuration applied consistently across systems.

Honeypot
Show answer

A decoy system used to detect, deflect, or study attackers.

Logging time synchronization
Show answer

Synchronizing clocks (e.g., NTP) so correlated logs have consistent, comparable timestamps.

Continuous monitoring
Show answer

Ongoing assessment of security controls and posture to detect drift and threats.

Legal, Risk & Compliance (42)

Conflicting international legislation
Show answer

Different countries' laws can impose contradictory obligations on cloud data — a key legal risk.

GDPR
Show answer

The EU General Data Protection Regulation governing the processing of personal data.

Data controller
Show answer

Under GDPR, the entity that decides why and how personal data is processed.

Data processor
Show answer

Under GDPR, a party that processes personal data on the controller's instructions (often the CSP).

PII
Show answer

Personally Identifiable Information — data that can identify an individual.

Regulated PII
Show answer

Personal data protected by law (e.g., HIPAA, GDPR) with statutory penalties for breach.

Contractual PII
Show answer

Personal data protected because a contract requires it (e.g., PCI DSS), with contractual consequences.

Regulated vs contractual PII
Show answer

Regulated PII is mandated by law; contractual PII is mandated by agreement.

ISO/IEC 27018
Show answer

A code of practice for protecting PII in public clouds acting as PII processors.

GAPP
Show answer

Generally Accepted Privacy Principles — a privacy management framework.

Privacy Impact Assessment (PIA)
Show answer

A structured assessment of the privacy risks of a system or process.

eDiscovery
Show answer

Identification, collection, and production of electronically stored information for legal matters.

SOC 1
Show answer

An attestation report on controls relevant to financial reporting.

SOC 2
Show answer

A report on controls for security, availability, processing integrity, confidentiality, and privacy.

SOC 3
Show answer

A public, summary version of a SOC 2 report with no sensitive detail.

SOC 2 Type I vs Type II
Show answer

Type I tests control design at a point in time; Type II tests operating effectiveness over a period.

Which SOC report for a CSP?
Show answer

SOC 2 — customers request it to assess a provider's security and privacy controls.

SSAE 18 / ISAE 3402
Show answer

Attestation standards under which SOC 1 reports are produced.

Gap analysis
Show answer

Comparing current controls against a required standard to find shortfalls.

Internal vs external audit
Show answer

Internal audit is performed by the organization; external audit by an independent third party.

ISMS
Show answer

Information Security Management System — a governed framework of policies and controls (ISO/IEC 27001).

ISO/IEC 27001
Show answer

The international standard for an Information Security Management System.

Right to audit
Show answer

A contract clause letting the customer assess a provider's controls (often satisfied by SOC 2 / ISO certs).

SLA
Show answer

Service Level Agreement — a contractual commitment on service performance and availability metrics.

Vendor lock-in
Show answer

Difficulty migrating away from a provider due to proprietary dependencies.

Cloud contract key clauses
Show answer

Right to audit, SLAs/metrics, data access/location, termination, litigation, insurance, and assurance.

Risk treatment options
Show answer

Avoid, mitigate, transfer/share, or accept the risk.

Risk appetite
Show answer

The amount of risk an organization is willing to accept in pursuit of its objectives.

Risk profile
Show answer

An organization's overall exposure to risk across its assets and activities.

ISO 31000
Show answer

An international standard providing principles and guidelines for risk management.

NIST RMF
Show answer

The NIST Risk Management Framework for selecting, implementing, and monitoring controls.

ENISA
Show answer

The European Union Agency for Cybersecurity, which publishes cloud risk guidance.

Distributed IT model impact
Show answer

Spreading control across a provider changes accountability and complicates risk management.

Supply-chain management (ISO/IEC 27036)
Show answer

Managing information security risk in supplier and outsourcing relationships.

Cyber risk insurance
Show answer

Insurance that transfers some financial impact of a cyber incident to an insurer.

Customer remains accountable
Show answer

Even when a provider holds the data, the customer stays accountable for protecting it.

Provider risk-program assessment
Show answer

Evaluating a provider's controls, methodologies, policies, risk profile, and risk appetite.

FedRAMP
Show answer

A U.S. government program standardizing the security assessment and authorization of cloud services.

Forensic requirements (legal)
Show answer

Contractual and legal obligations for collecting and preserving cloud evidence.

Cloud audit scope restriction
Show answer

Providers often limit what a customer audit can cover, hence reliance on third-party reports.

Termination clause (contract)
Show answer

Defines how a relationship ends and how data is returned or destroyed, reducing lock-in.

Geofencing data
Show answer

Restricting where data may be stored or accessed to meet residency/sovereignty rules.

References

  1. 1.ISC2. “CCSP Certification Exam Outline (effective October 1, 2025).” isc2.org. ↑
  2. 2.ISC2. “CCSP — Certified Cloud Security Professional.” isc2.org. ↑
  3. 3.Cloud Security Alliance. “Security Guidance for Critical Areas of Focus in Cloud Computing v4.0.” cloudsecurityalliance.org. ↑
Career Employer

Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.

Follow Us:

All Posts

Career Employer’s Editorial Process

Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.