The best response is to conduct a risk assessment and develop an impact analysis . The situation represents shadow IT and possible unauthorized cloud service use, but CISM emphasizes that the security manager should first understand the risk before deciding whether to allow, restrict, escalate, or formalize the service. A risk assessment identifies what data is being shared, who has access, what contractual protections exist, what privacy or regulatory obligations apply, and what threats may affect the service. An impact analysis helps determine potential business, legal, operational, and reputational consequences. Allowing temporary use and monitoring for leakage may expose the organization before risk is understood. Reporting immediately to senior management may be premature unless the risk is clearly severe. Updating the risk register is appropriate after the risk has been assessed and characterized. Therefore, conducting a risk assessment and impact analysis is the best response because it enables informed, risk-based decision-making about the unauthorized cloud collaboration service.
[References:, ISACA CISM Review Manual, Information Risk Management — shadow IT, cloud risk, and risk assessment, ISACA CISM Exam Content Outline, Domain 1: Information Risk Management, , ]
Submit