nerdexam
Isaca

CGEIT · Question #72

An audit report has revealed that data scientists are analyzing sensitive "big data" files using an offsite cloud because corporate servers do not have the necessary processing capabilities. A…

The correct answer is A. Authorize a risk analysis of the practice. The first strategic action to address the unauthorized use of an offsite cloud for sensitive data analysis, even if not explicitly prohibited, is to authorize a formal risk analysis of the practice.

Submitted by ngozi_ng· Apr 18, 2026Risk Optimization

Question

An audit report has revealed that data scientists are analyzing sensitive "big data" files using an offsite cloud because corporate servers do not have the necessary processing capabilities. A review of policies indicates this practice is not prohibited. Which of the following should be the FIRST strategic action to address the report?

Options

  • AAuthorize a risk analysis of the practice.
  • BUpdate data governance practices.
  • CRevise the information security policy.
  • DRecommend the use of a private cloud.

How the community answered

(26 responses)
  • A
    65% (17)
  • B
    4% (1)
  • C
    23% (6)
  • D
    8% (2)

Why each option

The first strategic action to address the unauthorized use of an offsite cloud for sensitive data analysis, even if not explicitly prohibited, is to authorize a formal risk analysis of the practice.

AAuthorize a risk analysis of the practice.Correct

Although the practice is not prohibited by current policies, using an offsite cloud for sensitive data without prior authorization or assessment introduces significant, unknown risks. A formal risk analysis is the necessary first step to understand the potential impact, likelihood, and existing controls (or lack thereof) before any other corrective or policy-related actions can be effectively planned.

BUpdate data governance practices.

Updating data governance practices would follow a risk analysis, as you need to understand the risks before defining appropriate governance.

CRevise the information security policy.

Revising the information security policy is a reactive measure that should be based on the findings of a comprehensive risk analysis.

DRecommend the use of a private cloud.

Recommending a private cloud is a potential solution, but it's premature without first understanding the risks of the current situation and the requirements for a secure alternative.

Concept tested: Prioritizing risk assessment in new IT practices

Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

Topics

#Risk analysis#Cloud governance#Policy gap#Strategic planning

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice