Certified Information Security Manager (CISM)Information Security Risk ManagementHard

An organization is considering deploying a new cloud-based application that will process highly sensitive customer data. The information security manager is conducting a risk assessment and identifies that the cloud provider's data encryption at rest uses a key management system (KMS) where the encryption keys are managed solely by the provider. Which of the following risk responses is MOST appropriate in this scenario?

  1. ATransfer the risk by purchasing cyber insurance.
  2. BRemediate the risk by requiring the cloud provider to implement customer-managed keys (CMK).
  3. CAvoid the risk by not deploying the application to the cloud.
  4. DAccept the risk, as encryption is being used by the cloud provider.
Show answer & explanation

Correct answer: B. Remediate the risk by requiring the cloud provider to implement customer-managed keys (CMK).

For highly sensitive data, relying solely on a cloud provider's managed encryption keys presents a potential risk of unauthorized access (e.g., via subpoena to the provider or insider threat). Requiring customer-managed keys (CMK) allows the organization to retain full control over the encryption keys, thus remediating a significant portion of this risk by ensuring only the organization can decrypt the data.

Why the other options are wrong

  • A. Cyber insurance transfers financial risk but doesn't address the underlying security control gap of key ownership for sensitive data.
  • C. Avoiding the cloud entirely might be an option, but 'remediate' is often preferred if a viable control can mitigate the risk to an acceptable level while still achieving business objectives.
  • D. Accepting this risk for highly sensitive data, especially when a stronger control exists, is generally not advisable.

Risk Treatment Options

Strategies an organization can employ to address identified risks, including avoidance, mitigation/remediation, transfer, and acceptance.

  • Should align with risk appetite.
  • Involves cost-benefit analysis.
  • Selected based on risk level and business impact.

Memory trick: Treat risks: Avoid, Mitigate, Transfer, Accept.

More Information Security Risk Management questions