The correct answer is C because before migrating a human resources application to the cloud, the information security manager should assess the cloud provider’s security capabilities, control environment, compliance posture, data protection practices, incident response process, access management, privacy protections, and contractual commitments. Human resources applications often process sensitive personal and employment information, so third-party and cloud risks must be evaluated before migration. Updating policies may be necessary later, but it does not determine whether the provider can adequately protect the data. Encrypting data is important, but encryption alone does not address all cloud risks such as access control, availability, segregation, monitoring, legal jurisdiction, breach notification, and vendor operations. Conducting vulnerability scans on the cloud provider may not be permitted and would provide only a narrow technical view. CISM emphasizes due diligence and risk assessment when outsourcing or using third-party services. Therefore, a security assessment of the cloud provider is the best way to support the migration securely.
[Reference: CISM Information Risk Management; cloud risk, third-party assessment, due diligence, data protection, and vendor security principles., , ]
Submit