nerdexam
Isaca

CISM · Question #452

An organization is migrating critical workloads to a multi-cloud environment subject to different regulatory and contractual requirements for data protection. Which of the following is the BEST…

The correct answer is B. Develop a unified cloud security framework that aims to be adaptable and flexible to different. In a multi-cloud environment with varied regulatory and contractual requirements, the best approach is to develop a unified cloud security framework that is flexible and adaptable to different compliance needs. This ensures consistent security controls, scalability, and…

Submitted by yousef_jo· Apr 18, 2026Information Security Governance

Question

An organization is migrating critical workloads to a multi-cloud environment subject to different regulatory and contractual requirements for data protection. Which of the following is the BEST course of action to ensure compliance in the multi-cloud environment?

Options

  • AUse cloud providers who comply with the strictest requirements among the different jurisdictions.
  • BDevelop a unified cloud security framework that aims to be adaptable and flexible to different
  • CConduct a gap analysis between the current cloud security posture and the various requirements.
  • DPrioritize cloud services provided in the jurisdiction where the organization's headquarters is

How the community answered

(41 responses)
  • A
    12% (5)
  • B
    59% (24)
  • C
    5% (2)
  • D
    24% (10)

Explanation

In a multi-cloud environment with varied regulatory and contractual requirements, the best approach is to develop a unified cloud security framework that is flexible and adaptable to different compliance needs. This ensures consistent security controls, scalability, and efficient risk management across multiple cloud providers while aligning with diverse regulatory mandates. While conducting a gap analysis and choosing strictest-compliant providers are useful, they do not offer a sustainable, long-term compliance strategy like a flexible security framework does.

Topics

#Multi-cloud security#Compliance management#Data protection#Security framework development

Community Discussion

No community discussion yet for this question.

Full CISM Practice