ExamGecko
Question list
Search
Search

Question 644 - CISM discussion

Report
Export

A small organization has a contract with a multinational cloud computing vendor. Which of the following would present the GREATEST concern to an information security manager if omitted from the contract?

A.
Authority of the subscriber to approve access to its data
Answers
A.
Authority of the subscriber to approve access to its data
B.
Right of the subscriber to conduct onsite audits of the vendor
Answers
B.
Right of the subscriber to conduct onsite audits of the vendor
C.
Commingling of subscribers' data on the same physical server
Answers
C.
Commingling of subscribers' data on the same physical server
D.
Escrow of software code with conditions for code release
Answers
D.
Escrow of software code with conditions for code release
Suggested answer: A

Explanation:

Authority of the subscriber to approve access to its data is the greatest concern for an information security manager if omitted from the contract, as it may expose the subscriber's data to unauthorized or inappropriate access by the vendor or third parties. The subscriber should have the right to control who can access its data, for what purposes, and under what conditions. The contract should also specify the vendor's obligations to protect the confidentiality, integrity, and availability of the subscriber's data, and to notify the subscriber of any breaches or incidents.

Reference= CISM Review Manual, 27th Edition, Chapter 4, Section 4.2.1, page 2201; Drafting and Negotiating Effective Cloud Computing Agreements2; CISM Online Review Course, Module 4, Lesson 2, Topic 13

asked 01/10/2024
GUY XAVIER DONGMO FAPONG
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first