nerdexam
Isaca

CISM · Question #623

Responsibility for risks associated with which of the following should be shared by both cloud customers and Software as a Service (SaaS) providers?

The correct answer is B. Access management. In a SaaS model, the shared responsibility model assigns most responsibilities to the provider - including infrastructure operations (C) and application development (A). Data classification (D) is primarily the customer's responsibility. Access management (B), however, is…

Submitted by ngozi_ng· Apr 18, 2026Information Security Risk Management

Question

Responsibility for risks associated with which of the following should be shared by both cloud customers and Software as a Service (SaaS) providers?

Options

  • AApplication development
  • BAccess management
  • CInfrastructure operations
  • DData classification

How the community answered

(57 responses)
  • A
    4% (2)
  • B
    93% (53)
  • C
    2% (1)
  • D
    2% (1)

Explanation

In a SaaS model, the shared responsibility model assigns most responsibilities to the provider - including infrastructure operations (C) and application development (A). Data classification (D) is primarily the customer's responsibility. Access management (B), however, is genuinely shared: the SaaS provider is responsible for securing platform-level authentication infrastructure, role-based access controls, and privileged access within the platform, while the customer is responsible for managing user identities, provisioning/deprovisioning accounts, and assigning appropriate permissions. Both parties must act for access management to be effective.

Topics

#Cloud Security#SaaS#Shared Responsibility Model#Access Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice