QuestionQ1750

Risk Assessment

What should be the risk practitioner’s FIRST action when an organization is planning to adopt a cloud-computing strategy?

  • A Perform a controls assessment.
  • B Request a budget for implementation.
  • C Conduct a threat analysis.
  • D Create a cloud computing policy.
Explanation

A threat analysis identifies the cloud-specific threat sources, vulnerabilities, and potential impacts that define the risk exposure. That analysis provides the basis for determining appropriate controls and subsequent governance measures.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!