From the course: Certificate of Cloud Security Knowledge (CCSK) Cert Prep
Unlock this course with a free trial
Join today to access over 25,500 courses taught by industry experts.
Cloud governance hierarchy
From the course: Certificate of Cloud Security Knowledge (CCSK) Cert Prep
Cloud governance hierarchy
- [Presenter] The governance hierarchy for cloud computing is a set of administrative controls that direct the roles, responsibilities, and accountabilities of decision-makers. At the top of the hierarchy is a selection of cybersecurity risk frameworks that can be used to manage risk. A few examples of risk frameworks include NIST Special Publications 800-30, which is the guide for conducting risk assessments, and ISO 27005, which is guidance on managing information security risk. Both provide high level structural approaches to risk management within an organization. NIST guidelines are free and required for use by US federal agencies. ISO guidelines are available for a fee and in some cases can be used to certify an organization's environment as meeting specific requirements. Additionally, you can consider the Cloud Security Alliance's Cloud Security Maturity Model, which is divided into three domains: foundational, structural, and procedural, each containing specific categories and…