Certified Information Security Manager (CISM)Information Security Risk ManagementHard
An organization is considering deploying a new cloud-based application that will process highly sensitive customer data. The information security manager is conducting a risk assessment and identifies that the cloud provider's data encryption at rest uses a key management system (KMS) where the encryption keys are managed solely by the provider. Which of the following risk responses is MOST appropriate in this scenario?
- ATransfer the risk by purchasing cyber insurance.
- BRemediate the risk by requiring the cloud provider to implement customer-managed keys (CMK).
- CAvoid the risk by not deploying the application to the cloud.
- DAccept the risk, as encryption is being used by the cloud provider.
Show answer & explanationAnswer & explanation
Correct answer: B. Remediate the risk by requiring the cloud provider to implement customer-managed keys (CMK).
For highly sensitive data, relying solely on a cloud provider's managed encryption keys presents a potential risk of unauthorized access (e.g., via subpoena to the provider or insider threat). Requiring customer-managed keys (CMK) allows the organization to retain full control over the encryption keys, thus remediating a significant portion of this risk by ensuring only the organization can decrypt the data.
Why the other options are wrong
- A. Cyber insurance transfers financial risk but doesn't address the underlying security control gap of key ownership for sensitive data.
- C. Avoiding the cloud entirely might be an option, but 'remediate' is often preferred if a viable control can mitigate the risk to an acceptable level while still achieving business objectives.
- D. Accepting this risk for highly sensitive data, especially when a stronger control exists, is generally not advisable.
Risk Treatment Options
Strategies an organization can employ to address identified risks, including avoidance, mitigation/remediation, transfer, and acceptance.
- Should align with risk appetite.
- Involves cost-benefit analysis.
- Selected based on risk level and business impact.
Memory trick: Treat risks: Avoid, Mitigate, Transfer, Accept.