CAS-002 · Question #233
The organization has an IT driver on cloud computing to improve delivery times for IT solution provisioning. Separate to this initiative, a business case has been approved for replacing the existing…
The correct answer is C. There may be regulatory restrictions with credit cards being processed out of country or. When evaluating cloud adoption for credit card processing, regulatory and data residency restrictions under PCI DSS must be assessed before approving cloud hosting for that workload.
Question
The organization has an IT driver on cloud computing to improve delivery times for IT solution provisioning. Separate to this initiative, a business case has been approved for replacing the existing banking platform for credit card processing with a newer offering. It is the security practitioner's responsibility to evaluate whether the new credit card processing platform can be hosted within a cloud environment. Which of the following BEST balances the security risk and IT drivers for cloud computing?
Options
- AA third-party cloud computing platform makes sense for new IT solutions.
- BUsing a third-party cloud computing environment should be endorsed going forward.
- CThere may be regulatory restrictions with credit cards being processed out of country or
- DCloud computing should rarely be considered an option for any processes that need to be
How the community answered
(62 responses)- A6% (4)
- B3% (2)
- C76% (47)
- D15% (9)
Why each option
When evaluating cloud adoption for credit card processing, regulatory and data residency restrictions under PCI DSS must be assessed before approving cloud hosting for that workload.
This statement is unconditionally broad - not all new IT solutions are appropriate for third-party cloud environments without first evaluating regulatory requirements and data sensitivity classifications.
Broadly endorsing third-party cloud without evaluating the specific compliance constraints applicable to credit card processing is irresponsible and potentially non-compliant with PCI DSS.
Credit card data processing is governed by PCI DSS, which imposes strict controls on where and how cardholder data is processed; additionally, many jurisdictions enforce data sovereignty laws that prohibit processing payment data outside specific national boundaries, making regulatory review essential before endorsing cloud hosting for this use case.
Categorically avoiding cloud for any sensitive process is overly restrictive and fails to balance the legitimate organizational IT driver for cloud adoption with a proportionate risk assessment.
Concept tested: Cloud adoption risk assessment for regulated payment data
Source: https://www.pcisecuritystandards.org/document_library/
Topics
Community Discussion
No community discussion yet for this question.