Certified Information Security Manager (CISM)Information Security ProgramMedium
An organization is migrating its data center operations to a cloud service provider (CSP). The CISO needs to ensure that the information security program effectively covers this new environment. Which of the following is the MOST important consideration for extending the security program to the cloud?
- AEnsuring the CSP's physical security controls meet industry best practices.
- BClearly defining and understanding the shared responsibility model with the CSP.
- CImplementing a robust Security Information and Event Management (SIEM) solution within the cloud environment.
- DDeveloping a new set of security policies exclusively for cloud-based assets.
Show answer & explanationAnswer & explanation
Correct answer: B. Clearly defining and understanding the shared responsibility model with the CSP.
The shared responsibility model is fundamental to cloud security, as it dictates what security aspects the CSP is responsible for and what the customer (the organization) must secure. A clear understanding prevents gaps and ensures full coverage of the security program.
Why the other options are wrong
- A. While important, physical security is generally the CSP's responsibility (part of the shared model), not the customer's primary concern.
- C. A SIEM is a valuable tool, but its effective deployment depends on first understanding the responsibility boundaries for data and infrastructure.
- D. New policies may be needed, but they must be based on the understanding of the shared responsibility model, making this a subsequent step.
Cloud Shared Responsibility Model
A framework that outlines the security obligations between a cloud service provider (CSP) and its customers, defining 'security of the cloud' (CSP) versus 'security in the cloud' (customer).
- Critical for cloud security planning.
- Prevents security gaps.
- Varies by service model (IaaS, PaaS, SaaS).
Memory trick: Shared Roles Secure Cloud.