Maps 10–12 — Monitoring, Cloud Accountability, Metrics
Map 10 — Monitoring and Audit
ACTIVE MONITORING ──> detect / alert / interrupt now ─┐
PASSIVE MONITORING ─> snapshots / trends later ──────┼─> EVIDENCE
│
INDEPENDENT AUDIT ───────────────────────────────────┘
evaluates evidence + compliance against requirements
Answer check: real-time block = Active; weekly trend = Passive; independent assurance = Audit.
Map 11 — Outsourcing / Cloud Accountability
ORGANIZATION RETAINS ACCOUNTABILITY
↓
Architecture + Classification
↓
Contract / SLA + Chain of Custody
+ CRUD / RACI + Right-to-Audit + Monitoring
↓
VENDOR / CLOUD IMPLEMENTS OR OPERATES CONTROLS
Exam discriminator: the map must never end with “vendor owns security now.” Control operation can be delegated; accountability remains.
Map 12 — Governance Measurement
Security Architecture
↓
Controls
↓
BASELINE METRICS
├─ Implementation
├─ Awareness
├─ Protection
├─ Incident
└─ Confidential Data Proliferation
↓
Findings / Decisions
↓
Improvement
Answer check: metrics must be actionable and baselined. More confidential copies are a security exposure even when primary systems are well protected.
Source anchors: Chapter 7 monitoring/audit, outsourcing/cloud, governance/metrics sections, pp. 243–255.