CGEIT Certified in the Governance of Enterprise IT – Question038

A business unit is planning to replace an existing IT legacy solution with a hosted Software as a Service (SaaS) solution. However, business management is concerned that stored data will be at risk. Which of the following would be the MOST effective way to reduce the risk associated with the SaaS solution?

A.
Include risk-related requirements in the SaaS contract.
B. Create key risk indicators for the SaaS solution.
C. Redefine the risk appetite and risk tolerance.
D. Research the technology and identify potential security threats.

Correct Answer: A