CRISC · Question #313
An organization's IT team has proposed the adoption of cloud computing as a cost-saving measure for the business. Which of the following should be of GREATEST concern to the risk practitioner?
The correct answer is A. Due diligence for the recommended cloud vendor has not been performed. The greatest concern when adopting cloud computing is the failure to perform due diligence on the cloud vendor, as this establishes the foundation for understanding and managing third-party risks.
Question
An organization's IT team has proposed the adoption of cloud computing as a cost-saving measure for the business. Which of the following should be of GREATEST concern to the risk practitioner?
Options
- ADue diligence for the recommended cloud vendor has not been performed.
- BThe business can introduce new Software as a Service (SaaS) solutions without IT approval.
- CThe maintenance of IT infrastructure has been outsourced to an Infrastructure as a Service (laaS)
- DArchitecture responsibilities may not be clearly defined.
How the community answered
(17 responses)- A59% (10)
- B6% (1)
- C12% (2)
- D24% (4)
Why each option
The greatest concern when adopting cloud computing is the failure to perform due diligence on the cloud vendor, as this establishes the foundation for understanding and managing third-party risks.
Performing thorough due diligence on a cloud vendor is the greatest concern because it involves comprehensively assessing the vendor's security posture, compliance, operational practices, and financial stability, which are all critical for understanding and managing the inherent risks introduced by relying on a third-party service.
While business units introducing SaaS without IT approval (shadow IT) is a significant risk, it is often a post-adoption challenge; the failure to vet the primary vendor at the proposal stage is a more fundamental and immediate concern for the initial adoption.
Outsourcing IaaS maintenance is an inherent aspect of the IaaS model and, while it shifts responsibilities, it is not the greatest concern if proper due diligence and contractual agreements are in place.
Unclear architecture responsibilities, though problematic, can be addressed through governance and design processes during implementation, whereas a lack of initial vendor vetting creates pervasive and potentially unmanageable risks from the outset.
Concept tested: Third-Party Risk Management / Vendor Due Diligence
Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/security-baseline/security-baseline-vendor-management
Topics
Community Discussion
No community discussion yet for this question.