How Should an ISM Support Cloud Application Migration?
An organization's human resources (HR) department is planning to migrate a legacy application to a new application in the cloud. What is the BEST way for the information security manager to support this effort?
Community Votes
67% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests third-party due diligence in cloud migrations, where candidates often mistakenly jump to updating internal policies or implementing encryption before evaluating the provider’s security posture.
When migrating legacy applications to the cloud, CISM candidates must prioritize third-party risk evaluation over immediate technical controls. The community consensus confirms that conducting a security assessment on the cloud provider is the optimal managerial step.
Option C (Updating policies) is frequently chosen because policy alignment seems proactive, but CISM prioritizes risk assessment and vendor due diligence as prerequisite steps before internal documentation changes.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The ISM operates from a governance and risk management perspective, requiring formal due diligence before any architectural changes. Conducting a security assessment on the cloud provider validates their compliance posture, data handling practices, and incident response capabilities, directly aligning with CISM Domain 3 risk management principles.Why the Other Options Are Wrong
Encrypting data (A) addresses confidentiality but ignores broader operational and compliance risks inherent in cloud adoption. Vulnerability scanning (B) is technically inappropriate without explicit authorization and fails to evaluate strategic vendor viability. Updating policies (C) prematurely assumes the new environment’s threat model without first validating the provider’s actual security controls.Community Comment Notes
Comment [1] correctly notes that migration requires evaluating the online application itself rather than assuming data-only concerns. Comment [2] argues for policy updates but overlooks that documentation changes must follow environmental validation. Comment [3] reinforces the consensus that risk assessment drives successful cloud transitions.Official Reference
Exam Strategy
Always filter cloud migration questions through the ISM lens: assess risk and vendor capability before deploying controls or rewriting policies. Look for options that emphasize due diligence, continuous monitoring, or contractual alignment over immediate technical fixes.
Frequently Asked Questions
Why is updating policies (C) not the best first step?
Policy updates require prior knowledge of the cloud environment’s specific threats and compliance requirements, making them a secondary step after vendor assessment.
Can we skip direct security assessments if the provider has SOC 2 reports?
Yes, leveraging existing third-party audit reports satisfies due diligence, but the ISM must still map those controls to internal risk appetite before migration.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →