ExamGecko
Question list
Search
Search

Question 612 - CISM discussion

Report
Export

Which of the following is the BEST way to ensure data is not co-mingled or exposed when using a cloud service provider?

A.
Obtain an independent audit report.
Answers
A.
Obtain an independent audit report.
B.
Require the provider to follow stringent data classification procedures.
Answers
B.
Require the provider to follow stringent data classification procedures.
C.
Include high penalties for security breaches in the contract.
Answers
C.
Include high penalties for security breaches in the contract.
D.
Review the provider's information security policies.
Answers
D.
Review the provider's information security policies.
Suggested answer: B

Explanation:

Requiring the provider to follow stringent data classification procedures is the BEST way to ensure data is not co-mingled or exposed when using a cloud service provider, because it helps to define the sensitivity and confidentiality levels of the data and the corresponding security controls and access policies that should be applied. Data classification procedures can help to prevent unauthorized access, disclosure, modification, or deletion of the data, as well as to segregate the data from other customers' data.

Reference=

CISM Review Manual, 16th Edition, ISACA, 2020, p. 72: ''Data classification is the process of assigning a level of sensitivity to data that reflects its importance and the impact of its disclosure, alteration, or destruction.''

CISM Review Manual, 16th Edition, ISACA, 2020, p. 73: ''Data classification should be based on the business requirements for confidentiality, integrity, and availability of the data, and should consider the legal, regulatory, and contractual obligations of the enterprise.''

Best Practices to Manage Risks in the Cloud - ISACA: ''Commingling of data: A big concern many enterprises have with public cloud services is the commingling of data with that of the cloud provider's other customers. One of your first questions should be: ''How do you ensure that my data is not commingled with others?'' How does the cloud provider ensure that only your team has access to your data?''

asked 01/10/2024
Laurence Peterson
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first