CGEIT · Question #437
An IT steering committee has received a report that supports the economic and service benefits of moving infrastructure hosting to an external cloud provider. Business leadership is very concerned abo
The correct answer is B. Include compliance with the enterprise's data governance policy in the contract.. To address concerns about security risk and customer data loss when moving to an external cloud, the IT steering committee should primarily include compliance with the enterprise's data governance policy in the contract.
Question
An IT steering committee has received a report that supports the economic and service benefits of moving infrastructure hosting to an external cloud provider. Business leadership is very concerned about the security risk and potential loss of customer data. What is the BEST way for the committee to address these concerns?
Options
- AMandate there will be no customer data at rest stored on cloud servers used by the vendor.
- BInclude compliance with the enterprise's data governance policy in the contract.
- CEnsure reporting and penalty clauses are included in the contract for any loss of data.
- DRequire an encrypted connection between the cloud and enterprise servers.
How the community answered
(25 responses)- A4% (1)
- B80% (20)
- C4% (1)
- D12% (3)
Why each option
To address concerns about security risk and customer data loss when moving to an external cloud, the IT steering committee should primarily include compliance with the enterprise's data governance policy in the contract.
Mandating no customer data at rest may be overly restrictive, potentially negating the benefits of cloud hosting, and might not be technically feasible or necessary if proper controls are in place.
Including compliance with the enterprise's data governance policy in the contract is the most comprehensive way to address business leadership's concerns, as it legally binds the cloud provider to adhere to the organization's standards for data handling, protection, and privacy across all stages. This ensures the cloud provider manages data consistent with the enterprise's established rules and regulatory obligations.
While reporting and penalty clauses are important for accountability, they are reactive measures after data loss occurs and do not proactively prevent or govern the handling of data.
Requiring an encrypted connection is a specific technical control for data in transit, but it does not address the broader concerns of data at rest, data processing, or overall governance within the cloud provider's environment.
Concept tested: Cloud vendor management and data governance
Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/data-governance/
Topics
Community Discussion
No community discussion yet for this question.