Certified Information Security Manager (CISM)Information Security ProgramMedium
An organization is migrating its proprietary data and applications to a public cloud provider. The CISO is responsible for ensuring the information security program effectively covers this new environment. Which of the following is the MOST critical initial step for the CISO to address regarding security responsibilities?
- AClearly defining and documenting the shared security responsibilities between the organization and the cloud provider.
- BImplementing a new set of security tools that are cloud-native and managed by the internal security team.
- CAuditing the cloud provider's physical security controls in their data centers.
- DNegotiating a Service Level Agreement (SLA) with the cloud provider for uptime guarantees.
Show answer & explanationAnswer & explanation
Correct answer: A. Clearly defining and documenting the shared security responsibilities between the organization and the cloud provider.
The 'shared responsibility model' is fundamental to cloud security. Before any other actions, the CISO must clearly define and document which security tasks fall to the organization and which to the cloud provider. Misunderstandings here lead to critical security gaps.
Why the other options are wrong
- B. Implementing new tools should happen after understanding the shared responsibilities, as the choice of tools will depend on what the organization is responsible for securing.
- C. While important, physical security is generally the cloud provider's responsibility. The CISO's primary initial concern is understanding where the responsibility line is drawn.
- D. SLAs primarily focus on service availability, not the division of security duties, which is a distinct and more critical initial security concern.
Cloud Shared Responsibility Model
A framework outlining the security obligations of a cloud service provider (CSP) and its customers, varying based on the service model (IaaS, PaaS, SaaS).
- CSP is responsible for 'security OF the cloud'.
- Customer is responsible for 'security IN the cloud'.
- Crucial for identifying and addressing security gaps.
Memory trick: Cloud's split duties: know who holds the security keys.