nerdexam
Isaca

CRISC · Question #313

An organization's IT team has proposed the adoption of cloud computing as a cost-saving measure for the business. Which of the following should be of GREATEST concern to the risk practitioner?

The correct answer is A. Due diligence for the recommended cloud vendor has not been performed. The greatest concern when adopting cloud computing is the failure to perform due diligence on the cloud vendor, as this establishes the foundation for understanding and managing third-party risks.

Submitted by kim_seoul· Apr 18, 2026Governance

Question

An organization's IT team has proposed the adoption of cloud computing as a cost-saving measure for the business. Which of the following should be of GREATEST concern to the risk practitioner?

Options

  • ADue diligence for the recommended cloud vendor has not been performed.
  • BThe business can introduce new Software as a Service (SaaS) solutions without IT approval.
  • CThe maintenance of IT infrastructure has been outsourced to an Infrastructure as a Service (laaS)
  • DArchitecture responsibilities may not be clearly defined.

How the community answered

(17 responses)
  • A
    59% (10)
  • B
    6% (1)
  • C
    12% (2)
  • D
    24% (4)

Why each option

The greatest concern when adopting cloud computing is the failure to perform due diligence on the cloud vendor, as this establishes the foundation for understanding and managing third-party risks.

ADue diligence for the recommended cloud vendor has not been performed.Correct

Performing thorough due diligence on a cloud vendor is the greatest concern because it involves comprehensively assessing the vendor's security posture, compliance, operational practices, and financial stability, which are all critical for understanding and managing the inherent risks introduced by relying on a third-party service.

BThe business can introduce new Software as a Service (SaaS) solutions without IT approval.

While business units introducing SaaS without IT approval (shadow IT) is a significant risk, it is often a post-adoption challenge; the failure to vet the primary vendor at the proposal stage is a more fundamental and immediate concern for the initial adoption.

CThe maintenance of IT infrastructure has been outsourced to an Infrastructure as a Service (laaS)

Outsourcing IaaS maintenance is an inherent aspect of the IaaS model and, while it shifts responsibilities, it is not the greatest concern if proper due diligence and contractual agreements are in place.

DArchitecture responsibilities may not be clearly defined.

Unclear architecture responsibilities, though problematic, can be addressed through governance and design processes during implementation, whereas a lack of initial vendor vetting creates pervasive and potentially unmanageable risks from the outset.

Concept tested: Third-Party Risk Management / Vendor Due Diligence

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/security-baseline/security-baseline-vendor-management

Topics

#Cloud Risk#Third-Party Risk Management#Vendor Due Diligence#Risk Governance

Community Discussion

No community discussion yet for this question.

Full CRISC Practice