ExamGecko
Question list
Search
Search

Question 501 - CISM discussion

Report
Export

What should be the GREATEST concern for an information security manager of a large multinational organization when outsourcing data processing to a cloud service provider?

A.
Vendor service level agreements (SLAs)
Answers
A.
Vendor service level agreements (SLAs)
B.
Independent review of the vendor
Answers
B.
Independent review of the vendor
C.
Local laws and regulations
Answers
C.
Local laws and regulations
D.
Backup and restoration of data
Answers
D.
Backup and restoration of data
Suggested answer: C

Explanation:

he greatest concern for an information security manager of a large multinational organization when outsourcing data processing to a cloud service provider is the local laws and regulations that may apply to the data and the cloud service provider. Local laws and regulations may vary significantly across different jurisdictions and may impose different requirements or restrictions on the data protection, privacy, security, sovereignty, retention, disclosure, transfer, or access. These laws and regulations may also create potential conflicts or inconsistencies with the organization's own policies, standards, or contractual obligations. Therefore, an information security manager should conduct a thorough legal and regulatory analysis before outsourcing data processing to a cloud service provider and ensure that the cloud service provider complies with all the applicable laws and regulations in the relevant jurisdictions.

Reference= CISM Manual1, Chapter 3: Information Security Program Development (ISPD), Section 3.1: Outsourcing2

1: https://store.isaca.org/s/store#/store/browse/cat/a2D4w00000Ac6NNEAZ/tiles2: 1

Outsourcing data processing to a cloud service provider may expose the organization to different legal and regulatory requirements depending on the location of the data and the vendor. This could affect the organization's compliance and liability in case of a breach or dispute. Therefore, the information security manager should be most concerned about the local laws and regulations that apply to the outsourcing arrangement.

asked 01/10/2024
Yusuf Sivrikaya
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first