ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITHard

A CISA is auditing an organization that uses a third-party cloud provider for its critical business applications. The organization's information security policy states that 'all data stored in the cloud must meet the same security standards as on-premise data.' However, the CISA finds no evidence of regular security audits or reviews of the cloud provider's environment by the organization. What is the MOST significant implication of this finding?

  1. AThe cloud provider might be operating inefficiently.
  2. BThe organization's internal IT staff skills may degrade over time.
  3. CThe organization's policy statement is effectively unenforceable and non-compliant.
  4. DThe organization may be overpaying for cloud services.
Show answer & explanation

Correct answer: C. The organization's policy statement is effectively unenforceable and non-compliant.

Without regular security audits or reviews of the cloud provider, the organization has no way to verify if its policy requirement ('same security standards as on-premise data') is actually being met. This renders the policy unenforceable in practice and exposes the organization to unknown security risks, making it non-compliant with its own stated policy.

Why the other options are wrong

  • A. Provider inefficiency is an operational concern, not the primary implication for the organization's security policy compliance.
  • B. Staff skill degradation is a long-term HR issue, not the direct and immediate implication of lacking cloud security oversight.
  • D. Cost is a separate issue from security assurance and policy enforcement.

Cloud Security Oversight

Cloud security oversight involves the organization's responsibility to ensure that cloud service providers adhere to its security policies and regulatory requirements through regular audits, reviews, and contractual agreements.

  • Shared responsibility model applies.
  • Requires contractual security clauses.
  • Verification through audits is essential.

Memory trick: Cloud security needs 'VERIFICATION' to make policy real.

More Domain 2: Governance and Management of IT questions