How Should an ISM Support Cloud Application Migration?

Cloud Security Governance & Third-Party Risk
Answer Correct answer: D — Conduct a comprehensive security assessment on the cloud provider to evaluate risks before migrating the HR application.

An organization's human resources (HR) department is planning to migrate a legacy application to a new application in the cloud. What is the BEST way for the information security manager to support this effort?

  1. Encrypt the data to the cloud so that the data is secure.
  2. Conduct vulnerability scans on the cloud provider.
  3. Update the policies to add controls for protecting the data.
  4. Conduct a security assessment on the cloud provider. Correct Answer

Community Votes

D
67%
C
33%

67% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests third-party due diligence in cloud migrations, where candidates often mistakenly jump to updating internal policies or implementing encryption before evaluating the provider’s security posture.

When migrating legacy applications to the cloud, CISM candidates must prioritize third-party risk evaluation over immediate technical controls. The community consensus confirms that conducting a security assessment on the cloud provider is the optimal managerial step.

Option C (Updating policies) is frequently chosen because policy alignment seems proactive, but CISM prioritizes risk assessment and vendor due diligence as prerequisite steps before internal documentation changes.

Community Discussion (3 comments)

Noragretz 👍 1 Selected: D
The question doesn’t say anything about migrating Data. Only switching (migrating) to an online application. Going with risk assessment on the SaaS cloud application.
Josef4CISM 👍 1 Selected: C
Its C, because moving an on premise application to the cloud involves a change in security strategy for that application, as the technological basis is different (cloud vs. on premise). Therefore, security documentation must be newly identified, documented and communicated to the cloud provider.
bronay 👍 1 Selected: D
Conduct risk assessment is the best way

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The ISM operates from a governance and risk management perspective, requiring formal due diligence before any architectural changes. Conducting a security assessment on the cloud provider validates their compliance posture, data handling practices, and incident response capabilities, directly aligning with CISM Domain 3 risk management principles.

Why the Other Options Are Wrong

Encrypting data (A) addresses confidentiality but ignores broader operational and compliance risks inherent in cloud adoption. Vulnerability scanning (B) is technically inappropriate without explicit authorization and fails to evaluate strategic vendor viability. Updating policies (C) prematurely assumes the new environment’s threat model without first validating the provider’s actual security controls.

Community Comment Notes

Comment [1] correctly notes that migration requires evaluating the online application itself rather than assuming data-only concerns. Comment [2] argues for policy updates but overlooks that documentation changes must follow environmental validation. Comment [3] reinforces the consensus that risk assessment drives successful cloud transitions.

Official Reference

Exam Strategy

Always filter cloud migration questions through the ISM lens: assess risk and vendor capability before deploying controls or rewriting policies. Look for options that emphasize due diligence, continuous monitoring, or contractual alignment over immediate technical fixes.

Frequently Asked Questions

Why is updating policies (C) not the best first step?

Policy updates require prior knowledge of the cloud environment’s specific threats and compliance requirements, making them a secondary step after vendor assessment.

Can we skip direct security assessments if the provider has SOC 2 reports?

Yes, leveraging existing third-party audit reports satisfies due diligence, but the ISM must still map those controls to internal risk appetite before migration.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide