nerdexam
Isaca

CISM · Question #249

Which of the following is the MOST critical consideration when shifting IT operations to an Infrastructure as a Service (IaaS) model hosted in a foreign country?

The correct answer is B. Laws and regulations of the origin country may not be applicable. When shifting IT operations to an IaaS provider in a foreign country, the most critical concern is that the host country's legal jurisdiction governs your data - your home country's privacy laws, compliance mandates (GDPR, HIPAA, etc.), and data protection regulations may have…

Submitted by lars.no· Apr 18, 2026Information Security Governance

Question

Which of the following is the MOST critical consideration when shifting IT operations to an Infrastructure as a Service (IaaS) model hosted in a foreign country?

Options

  • ALabeling of data may help to ensure data is assigned to the correct cloud type.
  • BLaws and regulations of the origin country may not be applicable.
  • CThere may be liabilities and penalties in the event of a security breach.
  • DData may be stored in unknown locations and may not be easily retrievable.

How the community answered

(24 responses)
  • A
    8% (2)
  • B
    67% (16)
  • C
    4% (1)
  • D
    21% (5)

Explanation

When shifting IT operations to an IaaS provider in a foreign country, the most critical concern is that the host country's legal jurisdiction governs your data - your home country's privacy laws, compliance mandates (GDPR, HIPAA, etc.), and data protection regulations may have no legal force there, fundamentally altering your risk posture and obligations.

Why the distractors fall short:

  • A - Data labeling is a useful governance practice, but it's an internal control that doesn't address the legal jurisdiction problem; labels don't change what laws apply.
  • C - Breach liabilities and penalties are real concerns, but they are a consequence of the jurisdictional issue in B, not the root consideration itself.
  • D - Unknown storage locations are a valid IaaS concern, but most providers offer data residency controls, and retrievability is a contractual/SLA issue - not the most critical factor.

Memory tip: Think of it as "crossing a border with your data." Just as your passport doesn't grant you home-country rights abroad, your compliance certifications don't travel with your data. When data crosses borders, local law rules - making jurisdiction the first thing to assess, not an afterthought.

Topics

#Cloud Computing#Legal Compliance#Data Sovereignty#Foreign Jurisdiction

Community Discussion

No community discussion yet for this question.

Full CISM Practice