CRISC Exam QuestionsBrowse all questions from this exam

CRISC Exam - Question 787


A global company's business continuity plan (BCP) requires the transfer of its customer information systems to an overseas cloud service provider in the event of a disaster. Which of the following should be the MOST important risk consideration?

Show Answer
Correct Answer: A

The most important risk consideration is the lack of a service level agreement (SLA) in the vendor contract. An SLA is crucial because it sets the expectations for the service quality, availability, and responsibilities of the cloud service provider. Without an SLA, there is no formal assurance of how the service provider will perform during a disaster, which is vital for business continuity in a global company.

Discussion

4 comments
Sign in to comment
CbtLOption: A
Apr 23, 2023

Agree it is A.

Silvias4Option: A
May 26, 2024

lack of a service level agreement (SLA) bigger risk

mynk29Option: B
May 24, 2023

A shared environment is a much bigger risk than SLA to my mind.

abhincarnationOption: B
Aug 11, 2023

B - bigger risk of confidential data being shared.