ExamGecko
Question list
Search
Search

Question 577 - CISM discussion

Report
Export

A small organization has a contract with a multinational cloud computing vendor. Which of the following would present the GREATEST concern to an information security manager if omitted from the contract?

A.
Right of the subscriber to conduct onsite audits of the vendor
Answers
A.
Right of the subscriber to conduct onsite audits of the vendor
B.
Escrow of software code with conditions for code release
Answers
B.
Escrow of software code with conditions for code release
C.
Authority of the subscriber to approve access to its data
Answers
C.
Authority of the subscriber to approve access to its data
D.
Commingling of subscribers' data on the same physical server
Answers
D.
Commingling of subscribers' data on the same physical server
Suggested answer: C

Explanation:

The greatest concern to an information security manager if omitted from the contract with a multinational cloud computing vendor would be the authority of the subscriber to approve access to its data. This is because the subscriber's data may be subject to different legal and regulatory requirements in different jurisdictions, and the subscriber may lose control over who can access, process, or disclose its data. The subscriber should have the right to approve or deny access to its data by the vendor or any third parties, and to ensure that the vendor complies with the applicable data protection laws and standards.The authority of the subscriber to approve access to its data is also one of the key elements of the ISACA Cloud Computing Management Audit/Assurance Program1.

Reference= CISM Review Manual, 16th Edition eBook2, Chapter 3: Information Security Program Development and Management, Section: Information Security Program Management, Subsection: Cloud Computing, Page 142.

asked 01/10/2024
Robert Thompson
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first