Leadership wants an annual independent report that shows stakeholders how the city's cloud security controls are designed and operating. Which approach fits that goal?
Select an answer to reveal the explanation.
Short Explanation
Stakeholders want a real report card, not a shrug. SOC 2, ISO 27001, or CSA-style assurance gives a structured way to show cloud controls—deleting evidence or posting root keys is the opposite of assurance.
Full Explanation
Organizations commonly demonstrate cloud security posture through established frameworks and attestation reports such as SOC 2, ISO 27001 certification programs, or Cloud Security Alliance guidance. These provide structured control criteria and evidence expectations. Destroying logs, informal undocumented claims, or exposing privileged credentials undermine assurance goals.