Isaca Certified Information Systems Auditor CISA Question # 293 Topic 30 Discussion
CISA Exam Topic 30 Question 293 Discussion:
Question #: 293
Topic #: 30
An IS auditor is reviewing the security of a web-based customer relationship management (CRM) system that is directly accessed by customers via the Internet, which of the following should be a concern for the auditor?
A.
The system is hosted on an external third-party service provider’s server.
B.
The system is hosted in a hybrid-cloud platform managed by a service provider.
C.
The system is hosted within a demilitarized zone (DMZ) of a corporate network.
D.
The system is hosted within an internal segment of a corporate network.
A web-based CRM system that is directly accessed by customers via the Internet should be hosted in a secure and isolated environment to protect it from external threats and unauthorized access. A web-based CRM system should also be reliable, trusted, and backedup regularly1.
Hosting the system on an external third-party service provider’s servers (A) or a hybrid-cloud platform managed by a service provider (B) may not be a concern for the auditor if the service provider has adequate security measures and service level agreements in place. The auditor should verify the security controls and contractual terms of the service provider before trusting them with the CRM data23.
Hosting the system within an internal segment of a corporate network (D) is a concern for the auditor because it exposes the CRM system and the internal network to potential attacks from the Internet. The CRM system should not be directly accessible from the Internet without a DMZ or a firewall to protect it. This could compromise the confidentiality, integrity, and availability of the CRM data and the internal network78.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit