Memory hook: Scope the promise, verify the evidence, plan the exit.
Must remember
Cloud data can cross storage, processing, support and backup jurisdictions. Identify applicable obligations with legal/privacy specialists; do not assume the selected storage region settles every issue. Distinguish ownership, controller, processor, custodian and stewardship responsibilities. A privacy impact assessment considers purpose, necessity, affected people and mitigation.
Contracts should define service boundaries, data use/ownership, security controls, subcontractors, breach notification, audit rights, service levels, evidence access, recovery, return/deletion and termination. An MSA supplies overarching terms; a statement of work defines specific delivery; an SLA defines measurable service commitments and remedies. A credit for downtime may be far smaller than business loss.
Evaluate SOC report type and scope. SOC 1 concerns controls relevant to financial reporting; SOC 2 addresses applicable trust-services criteria; a Type I report considers design at a point in time, whereas Type II includes operating effectiveness over a period. Read exceptions, subservice-organization treatment and complementary customer controls. Do not treat a logo as the report.
Legal holds and discovery requirements may override routine deletion. Negotiate preservation, export formats, access and chain-of-custody assistance before a dispute. Data sanitization in multitenant systems may rely on provider processes and cryptographic techniques; verify contractual assurance rather than demanding physical destruction of shared media indiscriminately.
Risk assessment includes provider viability, concentration, lock-in, supply chains and the organization's ability to operate securely. Insurance, escrow and alternate-provider plans address different consequences and have limitations. Assess an exit plan through tested exports and restoration, not only a termination clause.
Regulatory names are cues to scope, not interchangeable labels. Payment, health, financial and regional privacy obligations differ; certification questions test selecting an appropriate governance process rather than inventing a universal legal rule.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Supplier presents an audit badge | Read the actual report scope, period, exceptions and customer duties. |
| Business depends on one provider | Assess concentration and tested recovery/exit options. |
| Cross-border processing planned | Map data flows and obtain the relevant legal/privacy assessment. |
Traps
- An SLA remedy is not necessarily compensation for all damage.
- A contract cannot simply waive a law that applies to the organization.
Active recall
1. SOC 1 versus SOC 2?
SOC 1 focuses on relevant financial-reporting controls; SOC 2 addresses applicable trust-services criteria.
2. Type I versus Type II?
Point-in-time design versus design and operation over a period.
3. What must an exit clause address beyond cancellation?
Usable data return, keys/access, assistance, deletion evidence and transition timing.
4. Why map subcontractors?
They can introduce additional processing locations, access and contractual dependencies.
5. Who should resolve conflicting jurisdictional obligations?
Qualified legal/privacy owners with the business and security stakeholders.