ISACA Certified Information Systems Auditor (CISA) ExamDomain 4: Information Systems Operations and Business ResilienceHard
A global manufacturing company uses an Enterprise Resource Planning (ERP) system to manage its supply chain, production, and finance. The IS auditor observes that the ERP system is hosted in a public cloud environment, but the organization has not implemented any specific controls or agreements to ensure data residency requirements are met, despite operating in multiple countries with varying data protection laws. What is the MOST significant risk this oversight presents?
- ANon-compliance with data residency regulations, leading to legal and reputational damage.
- BIncreased latency and reduced performance for geographically dispersed users.
- CDifficulty in performing data analytics due to distributed data storage.
- DHigher cloud storage costs due to inefficient data placement strategies.
Show answer & explanationAnswer & explanation
Correct answer: A. Non-compliance with data residency regulations, leading to legal and reputational damage.
Many countries have strict data residency laws (e.g., GDPR, certain financial regulations) that require specific types of data to be stored within their borders. Failing to ensure this in a public cloud, especially for a global company, directly leads to severe legal penalties, fines, and reputational damage for non-compliance.
Why the other options are wrong
- B. Latency is a performance issue, not the primary risk of violating data residency requirements.
- C. Data analytics can be performed on distributed data, though it might require more complex tools; this is not the core risk of residency violations.
- D. Cost is a business concern but not the most significant risk when regulatory compliance is at stake.
Data Residency Requirements
Legal or regulatory stipulations that mandate specific data, particularly personal or sensitive information, must be stored and processed within the geographical boundaries of a particular country or region.
- Driven by national data protection laws (e.g., GDPR, CCPA).
- Impacts cloud service provider selection and configuration.
- Non-compliance can result in significant fines and legal action.
Memory trick: Data's home matters; if it roams, fines will foam.