QuestionQ433

Information Security Risk Management

An IT department is planning to migrate an application to the public cloud. What is the MOST important action for the information security manager to take in support of this initiative?

  • A Review cloud provider independent assessment reports.
  • B Provide cloud security requirements
  • C Evaluate service level agreements (SLAs)
  • D Calculate security implementation costs
Explanation

Before a cloud provider can be properly assessed, before SLAs can be meaningfully evaluated, and before implementation costs can be estimated, the organization must first define what security controls and protections it requires. The information security manager's most important contribution to a cloud migration is establishing and communicating the security requirements (e.g., data protection, access control, compliance, encryption, incident response expectations) that the cloud solution and provider must satisfy. These requirements then serve as the baseline for reviewing provider assessment reports and evaluating SLAs, making requirement-setting the foundational and most critical step in supporting a secure migration.

Community Discussion

No comments yet. Be the first to start the discussion!