Skip to content
ISC2 CCSP · CCSP

CCSP Domain 6: Legal, Risk and Compliance

Domain 6.0: Legal, Risk and Compliance · 13% of the exam

The domain that decides whether everything else is enforceable: all five objectives (6.1–6.5), from conflicting international legislation and eDiscovery, through privacy requirements and impact assessments, audit reports and what they actually cover, enterprise risk management and the five data roles, and the contract design that substitutes for the control you no longer hold.

5 modules · 34 topics 91-page PDF 50 practice questions
Read a free sample By the author of 51 Pluralsight courses · 4.6/5 from 2,007 ratings
Best value
$29/ month

All study guides, current and every new one.

or own the whole exam
$99one-time · all 6 domains
or just this guide
$24.95one-time · lifetime access
  • Interactive online guide
  • Downloadable PDF
  • Lifetime updates
  • 30-day money-back guarantee

Secure checkout via Stripe · no account needed · instant access

13% of your exam score

Domain 6.0 is worth 13% of the CCSP exam. Walk in having mastered it, not hoping it doesn't come up.

Every objective, nothing extra

Built line by line from the official ISC2 CCSP objectives 6.1–6.5: 34 in-depth topics with worked scenarios and exam tips, in a 91-page guide you'll actually finish.

50 exam-style questions

Every question comes with instant feedback and a full explanation, so a wrong answer teaches you as much as a right one.

The cloud credential, freshly rewritten

CCSP is the vendor-neutral cloud security certification, and the outline effective 1 August 2026 is brand new, with two AI objectives no incumbent book on the shelf covers.

Serving, transitioning, or a military spouse?

CCSP appears in the DoD 8140 qualification matrix. See how it maps to work roles, which credentialing program your branch runs, and what it will and will not pay for. Read the DoD 8140 guide →

Read a real excerpt, free

This is the actual opening of Module 6.1, Legal requirements and unique risks, not marketing copy. If you like how it teaches, the rest of the guide reads the same way.

Objective 6.1

Articulate legal requirements and unique risks within the cloud environment

Conflicting international legislation, forensics and eDiscovery obligations, and the legal risks that exist only because the infrastructure belongs to someone else.

Elin Haraldsóttir, Cobalt Grocery Group's group counsel, received two letters in the same month. The first was a preservation demand arising from a commercial dispute in a jurisdiction where Cobalt operated three stores. The second was a notice from a cloud provider that a new subprocessor, incorporated outside the European Economic Area, would begin performing support for one of the services Cobalt used.

The first letter required Cobalt to preserve and eventually produce data. The second changed who could reach it, and from where. Neither involved a security incident, and both were squarely security's problem — because the answers depended on where the data was, who could reach it, and whether Cobalt could prove either.

Exam focus · Jurisdiction attaches on several grounds at once

The organising idea for this whole domain. Obligations can attach because of where the data rests, where it transits, where the provider or its parent is incorporated, where the controller is established, and where the individuals are. All can apply simultaneously and can conflict. An answer that treats jurisdiction as a single question with a single answer — “the data is in Ireland, so Irish law applies” — is incomplete and usually wrong.

Conflicting international legislation

ConflictShape of the problem
Extraterritorial lawful accessA state compels a provider under its jurisdiction to produce data, including data held in another country, on the basis of the provider's incorporation or presence. The provider is then caught between that demand and the law where the data sits.
Blocking statutesLaws that prohibit disclosure of data to foreign authorities without going through recognised channels such as mutual legal assistance. Their purpose is precisely to create the conflict, so that the requesting state must use the treaty route.
Data localisationRequirements that certain categories of data be stored, and sometimes processed, only within a country's borders. Directly constrains cloud region selection and can make some managed services unusable.
Transfer restrictionsRules permitting transfer of personal data abroad only under recognised mechanisms — adequacy findings, standard contractual clauses with a transfer impact assessment, binding corporate rules or specific derogations. These mechanisms have been struck down before, which is itself a design risk.
Divergent breach and retention rulesDifferent deadlines, different thresholds, different retention minimums and maximums across the countries you operate in — nine, in Cobalt's case.
Sector rules crossing bordersFinancial services, health and critical infrastructure regimes that apply to the service regardless of where it is hosted.
The technical answer to a legal conflict

Where a provider can be compelled to produce data, the durable mitigation is architectural rather than contractual: if the provider holds no usable key, it can produce only ciphertext. Client-side encryption and hold-your-own-key arrangements convert a legal exposure into a technical impossibility, which is why the key-custody hierarchy from Domain 1 keeps reappearing. Contractual commitments to resist or notify are valuable and are not the same thing, because a provider can be prohibited from telling you.

The guide continues for 91 pagesKeep reading: unlock the full guide

Not ready to buy? Read it later.

We'll email you a free sample of this guide as a PDF, no purchase needed.

Try 3 sample questions

Pulled straight from the guide's 50-question bank. Tap an answer for instant feedback and the explanation.

From module 6.1 · Legal requirements and unique risks

  1. 1. Which statement about jurisdiction over cloud-hosted data is most accurate?

From module 6.2 · Privacy requirements

  1. 1. When must a data protection impact assessment be completed?

From module 6.3 · Audit processes and methodologies

  1. 1. An organization cites its provider's SOC 2 Type II as evidence of its own control effectiveness. What is the most likely audit finding?

47 more questions like these are waiting inside.

What's inside

  • 34 published sub-topics across 5 modules, mapped to objectives 6.1–6.5
  • 50 exam-style practice questions with instant feedback
  • Full answer key explaining why every distractor is wrong
  • SOC 1, 2 and 3, Type I and Type II, and what each really proves
  • Owner, controller, custodian, processor, steward: defined apart
  • Complete CCSP acronym & key-term reference
  • 91-page downloadable PDF for offline study and printing
  • Lifetime updates as the exam evolves

The modules, mapped to the objectives

  1. 6.1

    Legal requirements and unique risks

    Articulate legal requirements and unique risks within the cloud environment

    10 Qs
    Conflicting jurisdictionBlocking statutesLawful access demandseDiscovery & ISO/IEC 27050Legal hold in cloudTransfer mechanism risk
  2. 6.2

    Privacy requirements

    Understand privacy requirements

    10 Qs
    Regulated vs contractual dataController vs processorDPIA triggersISO/IEC 27018GAPPSpecial category data
  3. 6.3

    Audit processes and methodologies

    Understand audit processes, methodologies, and required adaptations for a cloud environment

    10 Qs
    SOC 1 / 2 / 3Type I vs Type IISSAE 18 & ISAE 3402/3000Complementary user entity controlsGap analysisContinuous control monitoring
  4. 6.4

    Cloud and enterprise risk management

    Understand implications of cloud to enterprise risk management

    10 Qs
    Data rolesRisk appetite vs toleranceKey risk indicatorsProvider risk programme assessmentConcentration riskRisk frameworks
  5. 6.5

    Outsourcing and cloud contract design

    Understand outsourcing and cloud contract design

    10 Qs
    MSA, SOW, SLAService credits & exclusionsRight to auditReversibility & data returnSource code escrowISO/IEC 27036
Chris Rees

About the author

Chris Rees

Professional information technologist with 25+ years in IT and the author of 51 certification training courses, 50+ live on Pluralsight, rated 4.6/5 across more than 2,000 reviews. This guide is that same exam-focused teaching, in a format you can finish.

More about Chris
All 6 CCSP domains

Sitting the whole exam? Get the Complete CCSP Collection.

Every domain of the exam, including this guide, for $99, one time.

See everything inside

Questions, answered

Do I need an account to buy?

No. Checkout is a single Stripe form: email and card, about 30 seconds. We create your access from your checkout email automatically and sign you in the moment payment completes.

Is this up to date with the real CCSP exam?

Yes. The guide is mapped module-by-module to the official ISC2 CCSP objectives (6.1–6.5), and lifetime updates are included, so as the exam evolves your guide does too.

What exactly do I get?

Instant access to the interactive online guide with all 50 practice questions, plus a 91-page PDF you can download, print, and keep forever.

Do I need the other domains too?

This guide covers Domain 6.0 (13% of the exam). To prepare for the whole exam, the Complete CCSP Collection bundles all 6 domains for $99, less than the price of three guides.

What if it isn't for me?

Every purchase comes with a 30-day money-back guarantee. Email us and we'll refund you, no hoops.

Who wrote it?

Chris Rees, a professional information technologist with 25+ years in IT and the author of 51 certification courses published on Pluralsight, rated 4.6/5 across 2,007 ratings.

Be ready for 13% of the exam, for $24.95

Instant access, lifetime updates, and a 30-day money-back guarantee. The only risk is walking into the exam without it.

Get the guide

Share this guide