An enterprise has decided to adopt cloud services. Which of the following should be established FIRST?
Before adopting cloud services, it is critical to establish the organization's risk tolerance levels. This ensures that decisions regarding the use of cloud services align with the enterprise's ability and willingness to accept risk, such as data exposure or operational disruptions. Risk tolerance informs the creation of SLAs, third-party management frameworks, and BCPs, making it a foundational step. Reference: ISACA Cloud Computing Governance guidelines, CGEIT Exam Manual.
Currently there are no comments in this discussion, be the first to comment!