nerdexam
Isaca

CRISC · Question #500

A risk practitioner is advising management on how to update the IT policy framework to account for the organization s cloud usage. Which of the following should be the FIRST step in this process?

The correct answer is C. Determine gaps between the current state and target framework. The first step in updating an IT policy framework for cloud usage is to determine the gaps between the organization's current policies and the desired target framework for cloud environments.

Submitted by ashley.k· Apr 18, 2026Governance

Question

A risk practitioner is advising management on how to update the IT policy framework to account for the organization s cloud usage. Which of the following should be the FIRST step in this process?

Options

  • AConsult with industry peers regarding cloud best practices.
  • BEvaluate adherence to existing IT policies and standards.
  • CDetermine gaps between the current state and target framework.
  • DAdopt an industry-leading cloud computing framework.

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    7% (2)
  • C
    75% (21)
  • D
    14% (4)

Why each option

The first step in updating an IT policy framework for cloud usage is to determine the gaps between the organization's current policies and the desired target framework for cloud environments.

AConsult with industry peers regarding cloud best practices.

Consulting with industry peers is a valuable input, but it occurs after understanding the internal context and identifying specific needs and gaps.

BEvaluate adherence to existing IT policies and standards.

Evaluating adherence to existing policies is an ongoing compliance activity, not the initial step in a policy update process driven by new technology adoption.

CDetermine gaps between the current state and target framework.Correct

Before any new policies are adopted or existing ones are revised, it's essential to understand the current state of policies, identify how they apply or fall short for cloud computing, and define the target state, thereby pinpointing the specific gaps that need to be addressed in the updated framework.

DAdopt an industry-leading cloud computing framework.

Adopting an industry-leading cloud computing framework should be considered after identifying internal needs and gaps, as a blanket adoption without a gap analysis may not fit the organization's specific context.

Concept tested: Policy framework update process

Source: https://www.isaca.org/resources/isaca-journal/issues/2021/volume-3/cloud-governance-challenges-and-best-practices

Topics

#Policy framework update#Cloud governance#Gap analysis#Risk management process

Community Discussion

No community discussion yet for this question.

Full CRISC Practice