Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CCSSADEMO Exam Feedback #41

Open
cyzen-io opened this issue Oct 27, 2018 · 0 comments
Open

CCSSADEMO Exam Feedback #41

cyzen-io opened this issue Oct 27, 2018 · 0 comments

Comments

@cyzen-io
Copy link

The test sample exam seems to provide a good structure and understanding of the framework and how a company should be aligned. While some examples are slightly unclear (specifically, there are times where an auditor may not understand why some controls don't score up to a level 3 or understand the higher level that the lowest score effects the overall highest possible score), this is a good example of how an exchange should be audited and how the overall controls should be analyzed.

It is also important to note that when auditing a specific client against this framework, one auditor may not assume the same risk as another which could lead to confusion. Specifically, the example given in the demo scenario of "When originally creating the business, the executive staff generated the seed for the Bitcoin wallet used in
the daily operation of their business over pizza and beer at the home of the Chief Technology Officer (CTO)." One auditor may assume this is secure since it is the private home of the CTO, a place that one would hope is as secure as possible. In theory, this is probably not the best place for this function to be conducted. That being said, this exam is also used to only grant the certificate to auditors who can satisfy the needs of C4 and that can demonstrate thorough knowledge of CCSS. It may be beneficial to require some analysis or understanding of other security frameworks (i.e. ISO27001 or the controls of ISO27002, NIST, etc.) to understand how to efficiently audit a client.

Overall the example provided provides a strong enough scenario for an auditor to analyze and provides the ability to assess if someone truly understands the framework.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant