nerdexam
Isaca

CGEIT · Question #584

An enterprise has decided to adopt cloud services. Which of the following should be established FIRST?

The correct answer is C. Risk tolerance levels. When adopting cloud services, establishing risk tolerance levels should be the first step, as it defines the acceptable level of risk for the organization before engaging with cloud providers or developing specific plans.

Submitted by valeria.br· Apr 18, 2026Risk Optimization

Question

An enterprise has decided to adopt cloud services. Which of the following should be established FIRST?

Options

  • AService level agreements (SLAs)
  • BBusiness continuity plan (BCP)
  • CRisk tolerance levels
  • DThird-party management framework

How the community answered

(22 responses)
  • A
    18% (4)
  • B
    5% (1)
  • C
    73% (16)
  • D
    5% (1)

Why each option

When adopting cloud services, establishing risk tolerance levels should be the first step, as it defines the acceptable level of risk for the organization before engaging with cloud providers or developing specific plans.

AService level agreements (SLAs)

Service Level Agreements (SLAs) define performance and availability metrics, but these can only be properly negotiated once the organization understands its risk tolerance and what level of service it requires to meet that tolerance.

BBusiness continuity plan (BCP)

A Business Continuity Plan (BCP) for cloud services is essential, but it must be developed with an understanding of the organization's risk tolerance; otherwise, it may be over-engineered or insufficient for the acceptable risk.

CRisk tolerance levelsCorrect

Before an enterprise can effectively adopt cloud services, it must first establish its risk tolerance levels. This foundational step defines the acceptable degree of potential loss or disruption that the organization is willing to bear, guiding all subsequent decisions regarding vendor selection, security controls, service level agreements, and business continuity planning in the cloud environment.

DThird-party management framework

A third-party management framework is crucial for managing cloud vendors, but its scope and requirements are heavily influenced by the organization's overall risk tolerance and how it views risks associated with external providers.

Concept tested: Cloud adoption foundational risk management

Topics

#Cloud adoption#Risk tolerance#IT governance#Strategic planning

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice