CAS-003 · Question #455
While conducting a BIA for a proposed acquisition, the IT integration team found that both companies outsource CRM services to competing and incompatible third-party cloud services. The decision has…
The correct answer is A. Data remnants D. Storage encryption. When migrating CRM data from cloud providers to an in-house solution, the CISO must focus on eliminating data remnants left on cloud storage and ensuring encryption of data at rest in the new environment.
Question
While conducting a BIA for a proposed acquisition, the IT integration team found that both companies outsource CRM services to competing and incompatible third-party cloud services. The decision has been made to bring the CRM service in-house, and the IT team has chosen a future solution. With which of the following should the Chief Information Security Officer (CISO) be MOST concerned? (Choose two.)
Options
- AData remnants
- BSovereignty
- CCompatible services
- DStorage encryption
- EData migration
- FChain of custody
How the community answered
(36 responses)- A75% (27)
- B6% (2)
- C3% (1)
- E3% (1)
- F14% (5)
Why each option
When migrating CRM data from cloud providers to an in-house solution, the CISO must focus on eliminating data remnants left on cloud storage and ensuring encryption of data at rest in the new environment.
Data remnants are residual pieces of sensitive customer data that remain on cloud provider storage infrastructure after the migration is complete; without verified data destruction or sanitization, the provider or future tenants could potentially access that data, creating a significant confidentiality risk.
Data sovereignty concerns apply primarily to cross-border data storage restrictions and are less critical when an organization is bringing data in-house within the same jurisdiction.
Compatible services is a technical integration concern for the IT migration team and does not represent a security risk that falls within the CISO's primary responsibility.
Storage encryption ensures that CRM data is protected at rest in the new in-house environment, so that even if physical or logical storage controls are bypassed, the data remains unreadable to unauthorized parties.
Data migration is a logistics and process concern for the IT team; the CISO's security focus centers on protecting data confidentiality and integrity before, during, and after migration rather than the migration process itself.
Chain of custody is a forensic evidence concept applicable to legal investigations and is not directly relevant to a CRM cloud-to-on-premises migration scenario.
Concept tested: Data remnants and storage encryption in cloud-to-on-premises migration
Source: https://csrc.nist.gov/publications/detail/sp/800-88/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.