Which of the following best describes a primary focus of cloud governance with an emphasis on security?
Correct Answer: D
Cloud governance focuses on security, risk management, and compliance to ensure data protection, audit readiness, and regulatory adherence.
Key Elements of Cloud Security Governance:
* Regulatory Compliance:
* Organizations must comply with GDPR, HIPAA, PCI DSS, ISO 27001.
* Cloud Security Posture Management (CSPM) helps enforce compliance automatically.
* Security Policies & Controls:
* Cloud governance frameworks include IAM (Identity and Access Management), encryption policies, and workload isolation.
* Organizations must standardize security settings across multiple cloud environments.
* Audit & Risk Management:
* Implement continuous monitoring, security logging, and forensic readiness.
* Risk-based access control policies ensure data security across workloads.
* Data Protection & Privacy:
* Enforcing cloud-native security frameworks (e.g., Zero Trust, CASB, SIEM).
* Data retention, access control, and incident response are essential governance practices.
This is covered in:
* CCSK v5 - Security Guidance v4.0, Domain 2 (Governance and Risk Management)
* Cloud Security Alliance's Cloud Controls Matrix (CCM) - Cloud Governance and Compliance Standards