QuestionQ145

Risk Optimization

A business unit in an enterprise has contracted directly with a cloud service provider to process sensitive customer information. The CIO subsequently identifies a serious potential data-compromise risk because the vendor has insufficient environment segregation and lacks strong access controls. The FIRST action should be to:

  • A immediately suspend sending of data to the cloud service provider.
  • B notify internal audit of the risk.
  • C discuss the risk with the vendor to determine mitigation actions.
  • D inform the business process owner of the risk.
Explanation

The business process owner owns the business risk arising from processing sensitive customer information through the cloud provider and must be informed promptly to decide on risk treatment. The owner can then authorize actions such as suspending transfers, requiring vendor remediation, or accepting/escalating the risk.

Community Discussion

No comments yet. Be the first to start the discussion!