CCSP Domain 6: Legal, Risk and Compliance
Domain 6.0: Legal, Risk and Compliance · 13% of the exam
The domain that decides whether everything else is enforceable: all five objectives (6.1–6.5), from conflicting international legislation and eDiscovery, through privacy requirements and impact assessments, audit reports and what they actually cover, enterprise risk management and the five data roles, and the contract design that substitutes for the control you no longer hold.
All study guides, current and every new one.
- Interactive online guide
- Downloadable PDF
- Lifetime updates
- 30-day money-back guarantee
Secure checkout via Stripe · no account needed · instant access
13% of your exam score
Domain 6.0 is worth 13% of the CCSP exam. Walk in having mastered it, not hoping it doesn't come up.
Every objective, nothing extra
Built line by line from the official ISC2 CCSP objectives 6.1–6.5: 34 in-depth topics with worked scenarios and exam tips, in a 91-page guide you'll actually finish.
50 exam-style questions
Every question comes with instant feedback and a full explanation, so a wrong answer teaches you as much as a right one.
The cloud credential, freshly rewritten
CCSP is the vendor-neutral cloud security certification, and the outline effective 1 August 2026 is brand new, with two AI objectives no incumbent book on the shelf covers.
Serving, transitioning, or a military spouse?
CCSP appears in the DoD 8140 qualification matrix. See how it maps to work roles, which credentialing program your branch runs, and what it will and will not pay for. Read the DoD 8140 guide →
Read a real excerpt, free
This is the actual opening of Module 6.1, Legal requirements and unique risks, not marketing copy. If you like how it teaches, the rest of the guide reads the same way.
Articulate legal requirements and unique risks within the cloud environment
Conflicting international legislation, forensics and eDiscovery obligations, and the legal risks that exist only because the infrastructure belongs to someone else.
Elin Haraldsóttir, Cobalt Grocery Group's group counsel, received two letters in the same month. The first was a preservation demand arising from a commercial dispute in a jurisdiction where Cobalt operated three stores. The second was a notice from a cloud provider that a new subprocessor, incorporated outside the European Economic Area, would begin performing support for one of the services Cobalt used.
The first letter required Cobalt to preserve and eventually produce data. The second changed who could reach it, and from where. Neither involved a security incident, and both were squarely security's problem — because the answers depended on where the data was, who could reach it, and whether Cobalt could prove either.
The organising idea for this whole domain. Obligations can attach because of where the data rests, where it transits, where the provider or its parent is incorporated, where the controller is established, and where the individuals are. All can apply simultaneously and can conflict. An answer that treats jurisdiction as a single question with a single answer — “the data is in Ireland, so Irish law applies” — is incomplete and usually wrong.
Conflicting international legislation
| Conflict | Shape of the problem |
|---|---|
| Extraterritorial lawful access | A state compels a provider under its jurisdiction to produce data, including data held in another country, on the basis of the provider's incorporation or presence. The provider is then caught between that demand and the law where the data sits. |
| Blocking statutes | Laws that prohibit disclosure of data to foreign authorities without going through recognised channels such as mutual legal assistance. Their purpose is precisely to create the conflict, so that the requesting state must use the treaty route. |
| Data localisation | Requirements that certain categories of data be stored, and sometimes processed, only within a country's borders. Directly constrains cloud region selection and can make some managed services unusable. |
| Transfer restrictions | Rules permitting transfer of personal data abroad only under recognised mechanisms — adequacy findings, standard contractual clauses with a transfer impact assessment, binding corporate rules or specific derogations. These mechanisms have been struck down before, which is itself a design risk. |
| Divergent breach and retention rules | Different deadlines, different thresholds, different retention minimums and maximums across the countries you operate in — nine, in Cobalt's case. |
| Sector rules crossing borders | Financial services, health and critical infrastructure regimes that apply to the service regardless of where it is hosted. |
Where a provider can be compelled to produce data, the durable mitigation is architectural rather than contractual: if the provider holds no usable key, it can produce only ciphertext. Client-side encryption and hold-your-own-key arrangements convert a legal exposure into a technical impossibility, which is why the key-custody hierarchy from Domain 1 keeps reappearing. Contractual commitments to resist or notify are valuable and are not the same thing, because a provider can be prohibited from telling you.
Not ready to buy? Read it later.
We'll email you a free sample of this guide as a PDF, no purchase needed.
Try 3 sample questions
Pulled straight from the guide's 50-question bank. Tap an answer for instant feedback and the explanation.
From module 6.1 · Legal requirements and unique risks
1. Which statement about jurisdiction over cloud-hosted data is most accurate?
From module 6.2 · Privacy requirements
1. When must a data protection impact assessment be completed?
From module 6.3 · Audit processes and methodologies
1. An organization cites its provider's SOC 2 Type II as evidence of its own control effectiveness. What is the most likely audit finding?
47 more questions like these are waiting inside.
What's inside
- 34 published sub-topics across 5 modules, mapped to objectives 6.1–6.5
- 50 exam-style practice questions with instant feedback
- Full answer key explaining why every distractor is wrong
- SOC 1, 2 and 3, Type I and Type II, and what each really proves
- Owner, controller, custodian, processor, steward: defined apart
- Complete CCSP acronym & key-term reference
- 91-page downloadable PDF for offline study and printing
- Lifetime updates as the exam evolves
The modules, mapped to the objectives
- 6.110 Qs
Legal requirements and unique risks
Articulate legal requirements and unique risks within the cloud environment
Conflicting jurisdictionBlocking statutesLawful access demandseDiscovery & ISO/IEC 27050Legal hold in cloudTransfer mechanism risk - 6.210 Qs
Privacy requirements
Understand privacy requirements
Regulated vs contractual dataController vs processorDPIA triggersISO/IEC 27018GAPPSpecial category data - 6.310 Qs
Audit processes and methodologies
Understand audit processes, methodologies, and required adaptations for a cloud environment
SOC 1 / 2 / 3Type I vs Type IISSAE 18 & ISAE 3402/3000Complementary user entity controlsGap analysisContinuous control monitoring - 6.410 Qs
Cloud and enterprise risk management
Understand implications of cloud to enterprise risk management
Data rolesRisk appetite vs toleranceKey risk indicatorsProvider risk programme assessmentConcentration riskRisk frameworks - 6.510 Qs
Outsourcing and cloud contract design
Understand outsourcing and cloud contract design
MSA, SOW, SLAService credits & exclusionsRight to auditReversibility & data returnSource code escrowISO/IEC 27036

About the author
Chris Rees
Professional information technologist with 25+ years in IT and the author of 51 certification training courses, 50+ live on Pluralsight, rated 4.6/5 across more than 2,000 reviews. This guide is that same exam-focused teaching, in a format you can finish.
More about ChrisSitting the whole exam? Get the Complete CCSP Collection.
Every domain of the exam, including this guide, for $99, one time.
See everything insideQuestions, answered
Do I need an account to buy?
No. Checkout is a single Stripe form: email and card, about 30 seconds. We create your access from your checkout email automatically and sign you in the moment payment completes.
Is this up to date with the real CCSP exam?
Yes. The guide is mapped module-by-module to the official ISC2 CCSP objectives (6.1–6.5), and lifetime updates are included, so as the exam evolves your guide does too.
What exactly do I get?
Instant access to the interactive online guide with all 50 practice questions, plus a 91-page PDF you can download, print, and keep forever.
Do I need the other domains too?
This guide covers Domain 6.0 (13% of the exam). To prepare for the whole exam, the Complete CCSP Collection bundles all 6 domains for $99, less than the price of three guides.
What if it isn't for me?
Every purchase comes with a 30-day money-back guarantee. Email us and we'll refund you, no hoops.
Who wrote it?
Chris Rees, a professional information technologist with 25+ years in IT and the author of 51 certification courses published on Pluralsight, rated 4.6/5 across 2,007 ratings.
Be ready for 13% of the exam, for $24.95
Instant access, lifetime updates, and a 30-day money-back guarantee. The only risk is walking into the exam without it.
Get the guide