Certified Information Security Manager CISM · Free Practice Question Medium

Question 105

Your organization is planning to adopt a cloud-based service to improve operational efficiency. What is the most crucial initial step for ensuring information security within this new environment?
  • A Enabling encryption for all data stored in the cloud
  • B Developing a security awareness training program for employees
  • C Performing a risk assessment to identify potential vulnerabilities and threats
  • D Implementing multifactor authentication for user access
Reveal correct answer

Correct answer: C

Explanation

The Correct Answer: Performing a risk assessment to identify potential vulnerabilities and threats: The most crucial initial step in adopting a cloud-based service is to understand the specific risks involved. A risk assessment provides insights into vulnerabilities and threats that could impact the organization. By identifying these risks early, the organization can develop targeted strategies to mitigate them, ensuring that the security measures implemented are effective and relevant to the specific cloud environment. The Incorrect Answers: Implementing multifactor authentication for user access: While important for ensuring secure access to systems, multifactor authentication is a specific control measure. Without first understanding the full spectrum of risks, relying solely on this measure may not address all potential threats associated with cloud services. Developing a security awareness training program for employees: Education is critical for maintaining security culture, but it should follow a comprehensive risk assessment. Training should be tailored to address identified risks relevant to the cloud service, ensuring employees understand and can mitigate these risks effectively. Enabling encryption for all data stored in the cloud: Encryption is a valuable security control, but it is only one part of a broader strategy. Without a risk assessment, it's difficult to tailor encryption policies effectively or prioritize their implementation amid other potential vulnerabilities and threats.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need