CISM Data Residency Practice Question
A multinational corporation is migrating its on-premises data center to a hybrid cloud environment. The organization processes highly sensitive financial data subject to strict regulatory requirements (e.g., GDPR, SOX). During the risk assessment, the information security manager discovers that the cloud service provider (CSP) stores data in multiple geographic regions, some of which do not meet the organization's data residency requirements. Additionally, the CSP's encryption key management is not fully under the organization's control, and the incident response plan does not include specific procedures for cloud-based breaches. The organization's risk appetite is low, and the board has mandated that all risks must be mitigated to an acceptable level. Which of the following is the BEST course of action?
⚠ Common exam trap
Candidates may mistakenly believe that accepting risk is viable when the CSP has strong certifications, but the board's mandate requires mitigation, not acceptance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require the CSP to provide dedicated hardware security modules and restrict data storage to approved regions through contractual terms
It directly addresses the root causes: data residency non-compliance and lack of control over encryption keys. Requiring dedicated hardware security modules (HSMs) and restricting data storage to approved regions through contractual terms ensures that the organization retains control over key management and meets regulatory requirements. This aligns with the low risk appetite and the board's mandate to mitigate risks to an acceptable level. Option B (accept the risk) is incorrect because it contradicts the board's mandate to mitigate all risks, and certifications alone do not guarantee compliance. Option C (cancel migration) is too drastic and costly; the organization can achieve compliance with the CSP rather than abandoning the cloud migration. Option D (transfer risk via insurance) does not achieve regulatory compliance; fines may still be imposed regardless of insurance coverage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Require the CSP to provide dedicated hardware security modules and restrict data storage to approved regions through contractual terms
Why this is correct
This directly mitigates the identified risks and aligns with the organization's low risk appetite.
- ✗
Accept the risk because the CSP has strong security certifications and the likelihood of a breach is low
Why it's wrong here
Acceptance violates the board's mandate to mitigate all risks and does not address regulatory compliance.
- ✗
Cancel the cloud migration and build a new private data center in a compliant location
Why it's wrong here
This is an extreme avoidance strategy that is likely more costly and disruptive than negotiating with the CSP.
- ✗
Transfer the risk by purchasing cyber insurance that covers regulatory fines
Why it's wrong here
Insurance does not prevent non-compliance; regulators may impose fines regardless.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 871-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.