CISA Certified Information Systems Auditor – Question2357

An organization is considering moving one of its critical business applications to a cloud hosting service. The cloud provider may not provide the same level of security for this application as the organization. Which of the following will provide the BEST information to help maintain the security posture?

A.
Risk assessment
B. Cloud security strategy
C. Vulnerability assessment
D. Risk governance framework

Correct Answer: A