ExamGecko
Question list
Search
Search

Question 183 - CISM discussion

Report
Export

Which of the following is the BEST approach to incident response for an organization migrating to a cloud-based solution?

A.
Adopt the cloud provider's incident response procedures.
Answers
A.
Adopt the cloud provider's incident response procedures.
B.
Transfer responsibility for incident response to the cloud provider.
Answers
B.
Transfer responsibility for incident response to the cloud provider.
C.
Continue using the existing incident response procedures.
Answers
C.
Continue using the existing incident response procedures.
D.
Revise incident response procedures to encompass the cloud environment.
Answers
D.
Revise incident response procedures to encompass the cloud environment.
Suggested answer: D

Explanation:

The best approach to incident response for an organization migrating to a cloud-based solution is to revise the existing incident response procedures to encompass the cloud environment. This is because the cloud environment introduces new challenges and risks that may not be adequately addressed by the current procedures. For example, the cloud provider may have different roles and responsibilities, service level agreements, notification and escalation processes, data protection and privacy requirements, and legal and regulatory obligations than the organization. Therefore, the organization should review and update its incident response procedures to align with the cloud provider's policies and practices, as well as the organization's business objectives and risk appetite. The organization should also ensure that the incident response team members are trained and aware of the changes in the procedures and the cloud environment.

The other options are not the best approaches because they do not consider the specific characteristics and implications of the cloud environment. Adopting the cloud provider's incident response procedures may not be feasible or desirable, as the organization may have different needs and expectations than the cloud provider. Transferring responsibility for incident response to the cloud provider may not be possible or advisable, as the organization may still retain some accountability and liability for the security and availability of its data and services in the cloud. Continuing to use the existing incident response procedures may not be effective or efficient, as the procedures may not cover the scenarios and issues that may arise in the cloud environment.Reference=

CISM Review Manual (Digital Version)1, Chapter 4: Information Security Incident Management, pages 191-192, 195-196, 199-200.

Cloud Incident Response Framework -- A Quick Guide2, pages 3-4, 6-7, 9-10.

CISM ITEM DEVELOPMENT GUIDE3, page 18, Question 1.

asked 01/10/2024
Ivan Ivanov
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first