An organization is implementing a new cloud-based enterprise resource planning (ERP) system. The CISA notes that the organization's existing information security policy, written for on-premise systems, has not been updated to reflect cloud-specific security considerations, shared responsibility models, or vendor contractual obligations. What is the MOST immediate governance concern?
- AIncreased training requirements for IT staff on cloud security principles.
- BInadequate security controls applied to the cloud ERP environment.
- CLack of clear guidelines for data residency and sovereignty in the cloud.
- DDifficulty in conducting effective security audits of the cloud provider.
Show answer & explanationAnswer & explanation
Correct answer: B. Inadequate security controls applied to the cloud ERP environment.
The most immediate governance concern is that without an updated policy tailored for cloud environments, the organization will likely apply inadequate or inappropriate security controls to the new cloud ERP. This leaves the system vulnerable as the existing policy (designed for on-premise) won't cover the unique risks and shared responsibilities of cloud computing, directly impacting the system's security posture.
Why the other options are wrong
- A. Training is a necessary step, but the policy itself needs to define *what* security measures are required before staff can be effectively trained to implement them.
- C. Data residency is a critical aspect, but the lack of an updated policy means fundamental controls might be missing, which is a broader concern.
- D. Auditing the cloud provider is a challenge, but the organization's own responsibility for security *within* the cloud (which the policy dictates) is more immediate.
Cloud Security Policy
Information security policies specifically adapted or developed for cloud computing environments, addressing unique aspects like shared responsibility models, data residency, vendor management, and cloud service configurations.
- Must reflect shared responsibility model.
- Covers cloud-specific risks and controls.
- Integrates with overall security governance.
Memory trick: Old policy, new cloud, big risks.