ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
While assessing a prospective SaaS provider, you receive only an ISO/IEC 27001 certificate and a brief penetration-test summary. To obtain detailed, cloud-focused evidence showing how the vendor's IAM, application security, and change-management controls map to recognized security domains, which additional artifact should you request?
An OWASP Application Security Verification Standard (ASVS) Level 2 assessment report
A SOC 1 Type II (SSAE 18) attestation report
A completed CSA Cloud Controls Matrix (CCM) or CAIQ mapping the provider's controls
A CVSS v3 vulnerability scorecard for recent penetration-test findings
The Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) and its associated CAIQ questionnaire provide a comprehensive set of cloud-specific control objectives mapped to multiple industry standards (e.g., ISO/IEC 27001, NIST 800-53). When a vendor completes the CCM/CAIQ, it documents how each of its cloud security controls aligns with these domains, giving the customer granular visibility into areas such as identity and access management, application security, and change management. An OWASP ASVS report focuses narrowly on application security and does not cover the breadth of cloud operational controls. A SOC 1 Type II report addresses financial reporting controls, not overall cloud security. A CVSS vulnerability scoring sheet lists specific flaws but does not map the organization's control environment to recognized cloud frameworks. Therefore, requesting the completed CSA CCM/CAIQ is the most effective way to assess the vendor's cloud control coverage.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the CSA Cloud Controls Matrix (CCM)?
Open an interactive chat with Bash
What is a CAIQ questionnaire?
Open an interactive chat with Bash
Why is a SOC 1 Type II report not suitable for assessing cloud security?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .