Certified Information Security Manager (CISM)Information Security Risk ManagementHard

An organization relies heavily on a third-party cloud provider for its critical data storage and processing. Recent news reports indicate a significant data breach at a similar cloud provider. The information security manager needs to assess the potential impact of this external event on the organization's risk posture. Which of the following is the MOST appropriate next step?

  1. AReview the contractual service level agreements (SLAs) with the current cloud provider for security guarantees.
  2. BConduct an updated risk assessment focusing on the specific risks highlighted by the external breach, in collaboration with the cloud provider.
  3. CRequest a copy of the cloud provider's latest penetration test report and audit findings.
  4. DImmediately migrate all critical data to an on-premise data center.
Show answer & explanation

Correct answer: B. Conduct an updated risk assessment focusing on the specific risks highlighted by the external breach, in collaboration with the cloud provider.

While reviewing SLAs and requesting reports (B and C) are good steps, they are reactive and provide limited insight into the specific, evolving threat. Migrating data (A) is an extreme, potentially unnecessary, and costly overreaction. The most appropriate and proactive step is to conduct an updated risk assessment (D) that specifically incorporates the new threat intelligence from the breach, ideally in collaboration with the provider to gain their specific insights and confirm their mitigation plans. This provides a comprehensive, tailored understanding of the current risk.

Why the other options are wrong

  • A. SLAs define responsibilities but don't actively assess the current threat or the provider's response to it in real-time.
  • C. While useful, past reports may not reflect the current threat landscape or the provider's response to the specific breach event.
  • D. This is an extreme and costly reaction without a full understanding of the specific risks to the organization.

Third-Party Risk Assessment

The process of identifying, analyzing, and evaluating risks introduced by external vendors, suppliers, or partners to an organization's information security.

  • Crucial for supply chain security.
  • Includes contractual and technical reviews.
  • Ongoing process, not a one-time event.

Memory trick: Don't just react, reassess with your partner.

More Information Security Risk Management questions