Certified Information Security Manager (CISM)Information Security ProgramMedium

An organization is migrating its critical applications to a cloud environment. The CISO is responsible for ensuring the security of these applications in the new infrastructure. To maintain a robust security posture, which of the following actions represents the MOST effective long-term strategy?

  1. ADeploy the same on-premise security tools directly into the cloud environment.
  2. BImplement a shared responsibility model, clearly defining roles and responsibilities with the CSP.
  3. COutsource all cloud security management to the cloud service provider (CSP).
  4. DFocus solely on network-level security controls provided by the CSP.
Show answer & explanation

Correct answer: B. Implement a shared responsibility model, clearly defining roles and responsibilities with the CSP.

The shared responsibility model is fundamental to cloud security. It clearly delineates what the CSP is responsible for (security *of* the cloud) and what the customer is responsible for (security *in* the cloud), enabling effective and comprehensive long-term security management.

Why the other options are wrong

  • A. Simply porting on-premise tools may not be optimal or effective in a cloud-native environment, which often requires different security approaches and tools.
  • C. Outsourcing all security to the CSP is generally not possible or advisable, as the customer always retains responsibility for their data and configurations.
  • D. Focusing solely on network security neglects other critical layers like application, data, and identity security, which are also the customer's responsibility in most cloud models.

Cloud Shared Responsibility Model

A framework that defines the division of security responsibilities between a cloud service provider (CSP) and its customers, clarifying who is accountable for different aspects of cloud security.

  • CSP is responsible for security *of* the cloud.
  • Customer is responsible for security *in* the cloud.
  • Responsibilities vary by cloud service model (IaaS, PaaS, SaaS).

Memory trick: In the cloud, security is a shared dance; both partners have their steps.

More Information Security Program questions