QuestionQ1104

Governance

An online retailer has chosen to store its customer database with a cloud provider using an Infrastructure as a Service (IaaS) configuration. During an initial review of preliminary risk scenarios, a risk practitioner identifies cases in which sensitive customer information is stored without encryption. Who is accountable for ensuring this encryption?

  • A The data owner
  • B The chief information officer (CIO)
  • C The retailer’s IT department
  • D The cloud provider
Explanation

In an IaaS arrangement, protection of customer data—including deciding and ensuring that sensitive information is encrypted—remains the customer organization’s responsibility. The data owner is accountable for establishing the required safeguards for that data.

Community Discussion

No comments yet. Be the first to start the discussion!