nerdexam
Isaca

CRISC · Question #293

Which of the following should be the PRIMARY driver for an organization on a multi-year cloud implementation to publish a cloud security policy?

The correct answer is B. Establishing minimum cloud security requirements. The primary driver for an organization to publish a cloud security policy during a multi-year cloud implementation should be to establish minimum cloud security requirements.

Submitted by carlos_mx· Apr 18, 2026Governance

Question

Which of the following should be the PRIMARY driver for an organization on a multi-year cloud implementation to publish a cloud security policy?

Options

  • AEvaluating gaps in the on-premise and cloud security profiles
  • BEstablishing minimum cloud security requirements
  • CEnforcing compliance with cloud security parameters
  • DEducating IT staff on variances between on premise and cloud security

How the community answered

(64 responses)
  • A
    11% (7)
  • B
    78% (50)
  • C
    6% (4)
  • D
    5% (3)

Why each option

The primary driver for an organization to publish a cloud security policy during a multi-year cloud implementation should be to establish minimum cloud security requirements.

AEvaluating gaps in the on-premise and cloud security profiles

Evaluating gaps is an assessment activity that helps inform policy development but is not the primary reason to publish the policy itself.

BEstablishing minimum cloud security requirementsCorrect

A cloud security policy's primary role is to establish a baseline of minimum security requirements and controls that all cloud resources, services, and operations must adhere to. This ensures a consistent security posture across the cloud environment from the outset, guiding implementation and mitigating fundamental risks.

CEnforcing compliance with cloud security parameters

Enforcing compliance with cloud security parameters is an outcome of having a policy, not the primary driver for creating it.

DEducating IT staff on variances between on premise and cloud security

Educating IT staff is an important function of a policy, but the policy's fundamental purpose is to set the requirements first.

Concept tested: Cloud Security Policy Purpose

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/secure/security-governance-policy-standards

Topics

#Cloud Security Policy#Security Governance#Cloud Implementation#Security Requirements

Community Discussion

No community discussion yet for this question.

Full CRISC Practice