Certified Information Security Manager (CISM)Information Security ProgramHard
A CISO is tasked with developing an information security program for an organization undergoing significant digital transformation, migrating many critical business functions to public cloud services. The organization's traditional on-premise security team lacks cloud expertise. Which of the following is the MOST critical initial step for the CISO to ensure the security program effectively supports this transformation?
- ADevelop a comprehensive cloud security strategy aligned with business objectives and cloud architecture.
- BConduct a detailed risk assessment of all applications and data being migrated to the cloud.
- CImplement a cloud access security broker (CASB) to monitor and enforce security policies for cloud services.
- DProvide extensive training to the existing security team on cloud security fundamentals and best practices.
Show answer & explanationAnswer & explanation
Correct answer: A. Develop a comprehensive cloud security strategy aligned with business objectives and cloud architecture.
Before implementing specific tools (CASB), training staff, or conducting risk assessments, a strategic direction is paramount. A comprehensive cloud security strategy ensures that security efforts are aligned with business objectives and the specific cloud architecture, providing a roadmap for all subsequent actions, especially given the lack of existing cloud expertise.
Why the other options are wrong
- B. A risk assessment is crucial, but it should be informed by a defined cloud security strategy to ensure it covers the relevant scope and priorities for the business.
- C. Implementing a CASB is a tactical step; without a strategy, its deployment might not align with overall business goals or the cloud architecture.
- D. Training is important, but without a clear strategy, the training might not be targeted effectively or aligned with the organization's specific cloud journey.
Cloud Security Strategy
A high-level plan that defines an organization's approach to securing cloud environments, aligned with business objectives, risk appetite, and the chosen cloud architecture.
- Foundation for all cloud security initiatives.
- Aligns security with business goals and cloud adoption.
- Guides technology choices, training, and risk management.
Memory trick: First the Map, then the Climb, then the Tools.