nerdexam
Isaca

CRISC · Question #583

A global organization is considering the transfer of its customer information systems to an overseas cloud service provider in the event of a disaster. Which of the following should be the MOST…

The correct answer is A. Regulatory restrictions for cross-border data transfer. When a global organization plans to transfer customer information to an overseas cloud service provider, the most critical risk consideration involves adhering to regulatory restrictions for cross-border data transfer.

Submitted by deeparc· Apr 18, 2026IT Risk Assessment

Question

A global organization is considering the transfer of its customer information systems to an overseas cloud service provider in the event of a disaster. Which of the following should be the MOST important risk consideration?

Options

  • ARegulatory restrictions for cross-border data transfer
  • BService level objectives in the vendor contract
  • COrganizational culture differences between each country
  • DManagement practices within each company

How the community answered

(33 responses)
  • A
    55% (18)
  • B
    27% (9)
  • C
    12% (4)
  • D
    6% (2)

Why each option

When a global organization plans to transfer customer information to an overseas cloud service provider, the most critical risk consideration involves adhering to regulatory restrictions for cross-border data transfer.

ARegulatory restrictions for cross-border data transferCorrect

Regulatory restrictions for cross-border data transfer are paramount because different countries have varying data residency, privacy, and sovereignty laws (e.g., GDPR, CCPA). Failing to comply with these regulations can lead to severe legal penalties, fines, and reputational damage for the organization, making it the most significant risk when moving customer data internationally.

BService level objectives in the vendor contract

Service level objectives (SLOs) are important for operational performance but secondary to legal compliance regarding data transfer itself.

COrganizational culture differences between each country

Organizational culture differences, while potentially impacting collaboration, are not the primary risk for data transfer compared to legal non-compliance.

DManagement practices within each company

Management practices within each company are relevant for overall vendor relationship management but do not supersede the legal requirements of data transfer.

Concept tested: Cross-border data transfer regulations

Source: https://learn.microsoft.com/en-us/compliance/regulatory/gdpr-data-protection-privacy-policies

Topics

#Regulatory compliance#Cross-border data transfer#Data privacy#Vendor risk management

Community Discussion

No community discussion yet for this question.

Full CRISC Practice