Articulate Legal Requirements
Understand Privacy Requirements
Understand Audit Processes
Understand Implications of Cloud to Enterprise Risk Management
Understand Outsourcing and Cloud Contract Design
100

One way organizations can navigate international cloud legislation which requires addressing the conflict between extraterritorial data demands and strict regional privacy mandates.

Customer-managed encryption and Sovereign cloud deployments

100

Individually identifiable health, treatment, or payment information protected by strict government laws.

Regulated PHI

100

It focuses on risk management, operational efficiency and integrity, improving practices and validating those practices against an industry standard

Internal audits

100

Organizations align these methodologies with legal, risk, and compliance goals by evaluating vendor controls, data sovereignty, regulatory adherence, and incident response capabilities to minimize liability.

CSP's Risk Management Program

100

It translates business requirements into operating metrics.

A Service Level Agreement (SLA)

200

Different countries have specific laws dictating where data must physically reside. Cloud environments make it harder to track physical asset locations without strict architectural controls.

Data Sovereignty & Residency

200

__________ expands or clarifies how health data can be used, shared, or protected between organizations beyond baseline rules which may fall outside strict statutory definitions

Contractual PHI

200

It provides an independent level of assurance to stakeholders that their systems and infrastructure are secure.

External audits

200

The internationally accepted cloud control framework

CSA CCM

200

It provides data center availability criteria and metrics

Uptime Institute  

300

A multi-part international standard that provides a comprehensive framework for electronic discovery (eDiscovery).

ISO/IEC 27050

300

A United States federal law protecting the privacy of student education records.

Family Educational Rights and Privacy Act (FERPA)

300

Because you generally cannot physically inspect a CSP’s data center, auditors rely on reviewing existing CSP-provided

 SOC 1 or SOC 2 reports

300

Map exactly where the provider stores and transfers your data to ensure compliance with regional regulations

Data Residency & Sovereignty

300

The difference between SMART metrics and SMART-R metrics

Realistic

400

A standardized framework to navigate cloud eDiscovery.

Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM)

400

Canada's federal private-sector privacy law.

PIPEDA (Personal Information Protection and Electronic Documents Act)

400

The current standard from the AICPA for auditing

SSAE 23

400

A central repository of all risks, including cloud risk

Risk register

400

It establishes the foundational legal and operational framework for business relationships, streamlining outsourcing and cloud contracts.

A Master Service Agreement (MSA)

500

To be legally defensible in court or for regulatory review, the __________ must be preserved.

chain of custody

500

Is a strictly US-centric federal law governing the use and disclosure of Protected Health Information (PHI).

HIPAA

500

The current international audit standard, equivalent to the AICPA's SOC 2

ISAE 3000

500

A U.S. Federal Government program established to oversee CSP's

FedRAMP

500

It dictates the specific scope, deliverables, and timelines of a cloud or outsourcing project, acting as the operational blueprint to mitigate legal, operational, and regulatory risks.

A Statement of Work (SOW)

M
e
n
u