CAS-001 · Question #28
The Chief Executive Officer (CEO) of a corporation decided to move all email to a cloud computing environment. The Chief Information Security Officer (CISO) was told to research the risk involved in…
The correct answer is B. Ensure logins are over an encrypted channel and obtain an NDA and an SLA from the cloud provider. Hosting email in the cloud requires both technical and contractual controls - encrypted communications protect data in transit while formal agreements with the provider establish accountability for data confidentiality and service availability.
Question
The Chief Executive Officer (CEO) of a corporation decided to move all email to a cloud computing environment. The Chief Information Security Officer (CISO) was told to research the risk involved in this environment. Which of the following measures should be implemented to minimize the risk of hosting email in the cloud?
Options
- ARemind users that all emails with sensitive information need be encrypted and physically inspect the
- BEnsure logins are over an encrypted channel and obtain an NDA and an SLA from the cloud provider.
- CEnsure logins are over an encrypted channel and remind users to encrypt all emails that contain sensitive
- DObtain an NDA from the cloud provider and remind users that all emails with sensitive information
How the community answered
(18 responses)- B83% (15)
- C11% (2)
- D6% (1)
Why each option
Hosting email in the cloud requires both technical and contractual controls - encrypted communications protect data in transit while formal agreements with the provider establish accountability for data confidentiality and service availability.
Physically inspecting a cloud provider's infrastructure is generally not feasible for a cloud customer and does not constitute a scalable or contractually enforceable security measure.
Ensuring logins occur over an encrypted channel (such as TLS) protects credentials and session data from interception, while obtaining a Non-Disclosure Agreement (NDA) legally obligates the cloud provider to protect company data confidentiality, and a Service Level Agreement (SLA) defines performance, availability, and security commitments - together these address both technical and governance risks of cloud email hosting.
Reminding users to encrypt sensitive emails is an informal control that lacks enforcement and does not establish any contractual accountability with the cloud provider for data protection.
An NDA alone without encryption of the login channel leaves credentials and data vulnerable to interception, and user reminders do not substitute for enforceable technical controls.
Concept tested: Cloud email security controls - encryption and provider agreements
Source: https://csrc.nist.gov/publications/detail/sp/800-144/final
Topics
Community Discussion
No community discussion yet for this question.