正解:D
Cloud governancefocuses onsecurity, risk management, and complianceto ensuredata protection, audit readiness, and regulatory adherence.
Key Elements of Cloud Security Governance:
* Regulatory Compliance:
* Organizations must comply withGDPR, HIPAA, PCI DSS, ISO 27001.
* Cloud Security Posture Management (CSPM)helpsenforce complianceautomatically.
* Security Policies & Controls:
* Cloud governance frameworks includeIAM (Identity and Access Management), encryption policies, and workload isolation.
* Organizations muststandardize security settingsacross multiple cloud environments.
* Audit & Risk Management:
* Implementcontinuous monitoring, security logging, and forensic readiness.
* Risk-based access control policiesensuredata security across workloads.
* Data Protection & Privacy:
* Enforcingcloud-native security frameworks (e.g., Zero Trust, CASB, SIEM).
* Data retention, access control, andincident responseareessential governance practices.
This is covered in:
* CCSK v5 - Security Guidance v4.0, Domain 2 (Governance and Risk Management)
* Cloud Security Alliance's Cloud Controls Matrix (CCM) - Cloud Governance and Compliance Standards