CISM Certified Information Security Manager – Question0347

An organization is considering moving one of its critical business applications to a cloud hosting service. The cloud provider may not provide the same level of security for this application as the organization. Which of the following will provide the BEST information to help maintain the security posture?

A.
Risk assessment
B. Cloud security strategy
C. Vulnerability assessment
D. Risk governance framework

Correct Answer: A