CRISC · Question #430
An organization uses a web application hosted by a cloud service that is populated by data sent to the vendor via email on a monthly basis. Which of the following should be the FIRST consideration…
The correct answer is C. Whether the data has been appropriately classified. The initial consideration when analyzing risk for an application that processes data is to determine the data's classification, as this dictates the necessary security controls and compliance requirements.
Question
An organization uses a web application hosted by a cloud service that is populated by data sent to the vendor via email on a monthly basis. Which of the following should be the FIRST consideration when analyzing the risk associated with the application?
Options
- AWhether the service provider's data center is located in the same country
- BWhether the data sent by email has been encrypted
- CWhether the data has been appropriately classified
- DWhether the service provider contract allows right of onsite audit
How the community answered
(53 responses)- A15% (8)
- B4% (2)
- C74% (39)
- D8% (4)
Why each option
The initial consideration when analyzing risk for an application that processes data is to determine the data's classification, as this dictates the necessary security controls and compliance requirements.
While data residency is important for compliance, the necessity of having the data center in the same country is directly dependent on the data's classification and associated regulatory requirements.
Whether the data sent by email has been encrypted is a control consideration, but the necessity and strength of that encryption are determined by the data's classification.
The first consideration should always be data classification because it determines the sensitivity, regulatory requirements, and the appropriate level of protection needed for the data. Knowing the data classification guides all subsequent risk analysis steps, including encryption requirements, jurisdictional concerns, and audit rights, by establishing the baseline criticality.
The service provider contract's allowance for a right of onsite audit is a critical oversight control, but its importance and focus are determined by the sensitivity and classification of the data being processed.
Concept tested: Data classification as first step in risk analysis
Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/data-classification-labeling
Topics
Community Discussion
No community discussion yet for this question.