Summary
In this chapter, you covered risk management across CSPs, various cloud service and deployment models, and the methods to identify, assess, and address risks, threats, and vulnerabilities. A CCSP candidate must be able to explain and implement risk management concepts, including understanding the risks associated with different cloud service models (IaaS, PaaS, and SaaS) and deployment models (public, private, hybrid, and community). They should be familiar with the shared responsibility model, common cloud risks, and industry-standard risk frameworks such as NIST RMF and ISO 31000:2018.
Additionally, candidates should know how to evaluate CSPs using tools such as CSA STAR and ISO 27001, differentiate between threats, vulnerabilities, and risks, and outline risk identification and assessment techniques. Best practices in risk countermeasures, understanding common cloud attack vectors and mitigation strategies, identifying threat actors, and IR in cloud computing are also...