IS 監査人が組織のクラウド アクセス セキュリティ ブローカー (CASB) ソリューションをレビューしています。監査人が検証する必要がある最も重要な項目は次のうちどれですか。
正解:D
Periodic recertification of users ensures that only authorized individuals retain access to cloud services and helps identify and revoke access for users who no longer require it. This is a critical control for maintaining security and compliance in a cloud environment. * Classifying Cloud Services (Option A):This is foundational but does not verify ongoing user access. * Centrally Managing Users (Option B):While useful for consistency, it does not assess whether access rights are still valid. * Ensuring Cloud Process Resilience (Option C):This focuses on operational continuity rather than access control. Periodic recertification aligns with governance practices to ensure access rights remain appropriate over time. Reference:ISACA CISA Review Manual, Job Practice Area 4: Protection of Information Assets.