nerdexam
Isaca

CISM · Question #371

What should an information security manager do FIRST when an organization is planning to use a third-party cloud computing service for a critical business process?

The correct answer is D. Perform a risk assessment. The first step is to perform a risk assessment to evaluate the potential risks associated with using the third-party cloud service for a critical business process. This ensures that security, compliance, and operational risks are identified and addressed before proceeding.

Submitted by stefanr· Apr 18, 2026Information Security Risk Management

Question

What should an information security manager do FIRST when an organization is planning to use a third-party cloud computing service for a critical business process?

Options

  • APerform a gap analysis.
  • BAnalyze the business requirements.
  • CIdentify the data to be hosted.
  • DPerform a risk assessment.

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    14% (4)
  • C
    7% (2)
  • D
    75% (21)

Explanation

The first step is to perform a risk assessment to evaluate the potential risks associated with using the third-party cloud service for a critical business process. This ensures that security, compliance, and operational risks are identified and addressed before proceeding.

Topics

#Cloud Security#Third-Party Risk Management#Risk Assessment#Security Program Planning

Community Discussion

No community discussion yet for this question.

Full CISM Practice