nerdexam
Isaca

CISM · Question #629

An information security manager is assessing security risk associated with a cloud service provider. Which of the following is the MOST appropriate reference to consult when performing this…

The correct answer is D. Security control frameworks. Security control frameworks (D) - such as ISO/IEC 27001, SOC 2 Type II, NIST CSF, or the CSA Cloud Controls Matrix (CCM) - provide comprehensive, standardized, and vendor-neutral criteria for evaluating whether a cloud provider has adequate controls in place. They enable…

Submitted by kev92· Apr 18, 2026Information Security Risk Management

Question

An information security manager is assessing security risk associated with a cloud service provider. Which of the following is the MOST appropriate reference to consult when performing this assessment?

Options

  • APrevious provider service level agreements (SLAs)
  • BPenetration test results from the provider
  • CThreat intelligence reports
  • DSecurity control frameworks

How the community answered

(34 responses)
  • A
    9% (3)
  • B
    18% (6)
  • C
    3% (1)
  • D
    71% (24)

Explanation

Security control frameworks (D) - such as ISO/IEC 27001, SOC 2 Type II, NIST CSF, or the CSA Cloud Controls Matrix (CCM) - provide comprehensive, standardized, and vendor-neutral criteria for evaluating whether a cloud provider has adequate controls in place. They enable consistent, repeatable assessments against industry-accepted benchmarks. Previous SLAs (A) address service availability commitments, not security control adequacy. Penetration test results (B) are point-in-time assessments of specific attack vectors and not a holistic view of the provider's control environment. Threat intelligence reports (C) inform the threat landscape but do not evaluate the provider's internal controls. Frameworks are the authoritative reference for a structured risk assessment.

Topics

#Cloud security#Risk assessment#Security control frameworks#Vendor risk management

Community Discussion

No community discussion yet for this question.

Full CISM Practice