A customer has a contract with a CSP and wants to identify which controls should be implemented in the IaaS enclave. Which of the following is most likely to contain this information?
Choose an answer
Tap an option to check your answer.
Correct answer: Responsibility matrix.
Why this is the answer
A responsibility matrix (or RACI matrix) clearly defines the roles and responsibilities of both the cloud service provider (CSP) and the customer for various security controls and tasks within a cloud environment, including an IaaS enclave. It specifies who is Responsible, Accountable, Consulted, and Informed for each control, making it the most direct source for identifying which controls the customer needs to implement. A statement of work (SOW) outlines the project-specific tasks, deliverables, and timelines but typically doesn't detail shared security responsibilities. A service-level agreement (SLA) defines performance metrics, uptime guarantees, and penalties, not specific control implementations. A master service agreement (MSA) is a high-level contract that sets the general terms and conditions for all services between parties but lacks the granular detail of control ownership.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed