Courseiva
Information Security Risk ManagementhardMultiple ChoiceObjective-mapped

CISM Data Residency Practice Question

A multinational corporation is migrating its on-premises data center to a hybrid cloud environment. The organization processes highly sensitive financial data subject to strict regulatory requirements (e.g., GDPR, SOX). During the risk assessment, the information security manager discovers that the cloud service provider (CSP) stores data in multiple geographic regions, some of which do not meet the organization's data residency requirements. Additionally, the CSP's encryption key management is not fully under the organization's control, and the incident response plan does not include specific procedures for cloud-based breaches. The organization's risk appetite is low, and the board has mandated that all risks must be mitigated to an acceptable level. Which of the following is the BEST course of action?

⚠ Common exam trap

Candidates may mistakenly believe that accepting risk is viable when the CSP has strong certifications, but the board's mandate requires mitigation, not acceptance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Require the CSP to provide dedicated hardware security modules and restrict data storage to approved regions through contractual terms

It directly addresses the root causes: data residency non-compliance and lack of control over encryption keys. Requiring dedicated hardware security modules (HSMs) and restricting data storage to approved regions through contractual terms ensures that the organization retains control over key management and meets regulatory requirements. This aligns with the low risk appetite and the board's mandate to mitigate risks to an acceptable level. Option B (accept the risk) is incorrect because it contradicts the board's mandate to mitigate all risks, and certifications alone do not guarantee compliance. Option C (cancel migration) is too drastic and costly; the organization can achieve compliance with the CSP rather than abandoning the cloud migration. Option D (transfer risk via insurance) does not achieve regulatory compliance; fines may still be imposed regardless of insurance coverage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Require the CSP to provide dedicated hardware security modules and restrict data storage to approved regions through contractual terms

    Why this is correct

    This directly mitigates the identified risks and aligns with the organization's low risk appetite.

  • Accept the risk because the CSP has strong security certifications and the likelihood of a breach is low

    Why it's wrong here

    Acceptance violates the board's mandate to mitigate all risks and does not address regulatory compliance.

  • Cancel the cloud migration and build a new private data center in a compliant location

    Why it's wrong here

    This is an extreme avoidance strategy that is likely more costly and disruptive than negotiating with the CSP.

  • Transfer the risk by purchasing cyber insurance that covers regulatory fines

    Why it's wrong here

    Insurance does not prevent non-compliance; regulators may impose fines regardless.

About these practice questions

This CISM question is part of Courseiva's 871-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.