Certified Information Security Manager (CISM)Information Security ProgramHard

A CISO is tasked with developing an information security program for an organization undergoing significant digital transformation, migrating many critical business functions to public cloud services. The organization's traditional on-premise security team lacks cloud expertise. Which of the following is the MOST critical initial step for the CISO to ensure the security program effectively supports this transformation?

  1. ADevelop a comprehensive cloud security strategy aligned with business objectives and cloud architecture.
  2. BConduct a detailed risk assessment of all applications and data being migrated to the cloud.
  3. CImplement a cloud access security broker (CASB) to monitor and enforce security policies for cloud services.
  4. DProvide extensive training to the existing security team on cloud security fundamentals and best practices.
Show answer & explanation

Correct answer: A. Develop a comprehensive cloud security strategy aligned with business objectives and cloud architecture.

Before implementing specific tools (CASB), training staff, or conducting risk assessments, a strategic direction is paramount. A comprehensive cloud security strategy ensures that security efforts are aligned with business objectives and the specific cloud architecture, providing a roadmap for all subsequent actions, especially given the lack of existing cloud expertise.

Why the other options are wrong

  • B. A risk assessment is crucial, but it should be informed by a defined cloud security strategy to ensure it covers the relevant scope and priorities for the business.
  • C. Implementing a CASB is a tactical step; without a strategy, its deployment might not align with overall business goals or the cloud architecture.
  • D. Training is important, but without a clear strategy, the training might not be targeted effectively or aligned with the organization's specific cloud journey.

Cloud Security Strategy

A high-level plan that defines an organization's approach to securing cloud environments, aligned with business objectives, risk appetite, and the chosen cloud architecture.

  • Foundation for all cloud security initiatives.
  • Aligns security with business goals and cloud adoption.
  • Guides technology choices, training, and risk management.

Memory trick: First the Map, then the Climb, then the Tools.

More Information Security Program questions