nerdexam
Isaca

CGEIT · Question #437

An IT steering committee has received a report that supports the economic and service benefits of moving infrastructure hosting to an external cloud provider. Business leadership is very concerned abo

The correct answer is B. Include compliance with the enterprise's data governance policy in the contract.. To address concerns about security risk and customer data loss when moving to an external cloud, the IT steering committee should primarily include compliance with the enterprise's data governance policy in the contract.

Submitted by akirajp· Apr 18, 2026Governance of Enterprise IT

Question

An IT steering committee has received a report that supports the economic and service benefits of moving infrastructure hosting to an external cloud provider. Business leadership is very concerned about the security risk and potential loss of customer data. What is the BEST way for the committee to address these concerns?

Options

  • AMandate there will be no customer data at rest stored on cloud servers used by the vendor.
  • BInclude compliance with the enterprise's data governance policy in the contract.
  • CEnsure reporting and penalty clauses are included in the contract for any loss of data.
  • DRequire an encrypted connection between the cloud and enterprise servers.

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    80% (20)
  • C
    4% (1)
  • D
    12% (3)

Why each option

To address concerns about security risk and customer data loss when moving to an external cloud, the IT steering committee should primarily include compliance with the enterprise's data governance policy in the contract.

AMandate there will be no customer data at rest stored on cloud servers used by the vendor.

Mandating no customer data at rest may be overly restrictive, potentially negating the benefits of cloud hosting, and might not be technically feasible or necessary if proper controls are in place.

BInclude compliance with the enterprise's data governance policy in the contract.Correct

Including compliance with the enterprise's data governance policy in the contract is the most comprehensive way to address business leadership's concerns, as it legally binds the cloud provider to adhere to the organization's standards for data handling, protection, and privacy across all stages. This ensures the cloud provider manages data consistent with the enterprise's established rules and regulatory obligations.

CEnsure reporting and penalty clauses are included in the contract for any loss of data.

While reporting and penalty clauses are important for accountability, they are reactive measures after data loss occurs and do not proactively prevent or govern the handling of data.

DRequire an encrypted connection between the cloud and enterprise servers.

Requiring an encrypted connection is a specific technical control for data in transit, but it does not address the broader concerns of data at rest, data processing, or overall governance within the cloud provider's environment.

Concept tested: Cloud vendor management and data governance

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/data-governance/

Topics

#Cloud Security#Data Governance#Third-Party Risk#Contractual Agreements

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice