Certified Information Security Manager (CISM)Information Security GovernanceHard

An organization is migrating its core business applications to a multi-cloud environment. The CISO is concerned about maintaining consistent information security governance across these diverse platforms. Which of the following is the MOST effective approach to address this concern?

  1. AImplement a cloud access security broker (CASB) to enforce uniform security policies.
  2. BEstablish a centralized cloud security posture management (CSPM) solution.
  3. CDevelop separate, tailored security policies and controls for each cloud provider.
  4. DAdopt a single global security framework and adapt it for all cloud environments.
Show answer & explanation

Correct answer: D. Adopt a single global security framework and adapt it for all cloud environments.

Adopting a single global security framework and adapting it for all cloud environments is the MOST effective approach. This provides a consistent overarching governance model, allowing for standardized policy application, while still permitting necessary adaptations for specific cloud platforms.

Why the other options are wrong

  • A. A CASB is a technical control for enforcing policies, but it doesn't establish the overarching governance framework or strategy.
  • B. A CSPM solution helps monitor and manage security posture, but it's a tool that supports governance, not the governance framework itself.
  • C. Separate policies can lead to inconsistency, increased complexity, and potential security gaps across the multi-cloud environment.

Multi-Cloud Governance

The strategy and processes for ensuring consistent and effective information security oversight, risk management, and compliance across multiple disparate cloud service providers and environments.

  • Aims for consistency while allowing flexibility.
  • Leverages overarching frameworks.
  • Addresses shared responsibility model complexities.

Memory trick: One rulebook for many clouds, with flexible interpretations.

More Information Security Governance questions