nerdexam
Isaca

CISM · Question #331

What is the BEST way to address the risk of residual data on hardware being incorrectly disposed of by a cloud service provider?

The correct answer is A. Include a data destruction clause in the contract.. When hardware is managed by a cloud service provider, the organization has no direct physical control over decommissioning or disposal processes. The most effective way to address residual data risk is to include a contractual data destruction clause, which legally obligates the

Submitted by ahmad_uae· Apr 18, 2026Information Security Risk Management

Question

What is the BEST way to address the risk of residual data on hardware being incorrectly disposed of by a cloud service provider?

Options

  • AInclude a data destruction clause in the contract.
  • BReview use of independent data destruction vendors.
  • CRequire encryption of data at rest.
  • DReview data retention policies and procedures.

How the community answered

(38 responses)
  • A
    71% (27)
  • B
    8% (3)
  • C
    16% (6)
  • D
    5% (2)

Explanation

When hardware is managed by a cloud service provider, the organization has no direct physical control over decommissioning or disposal processes. The most effective way to address residual data risk is to include a contractual data destruction clause, which legally obligates the provider to follow approved data sanitization or destruction procedures and provide certification of compliance. Encryption at rest (C) reduces exposure but does not prevent residual data if key management is mishandled or keys are retained. Reviewing independent vendors (B) is a secondary due-diligence step, not a primary control. Reviewing retention policies (D) governs how long data is kept, not how it is destroyed at end-of-life.

Topics

#Cloud Security#Data Destruction#Third-Party Risk#Contract Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice