クラウド サービス プロバイダーである A 社は、自社のクラウド サービスに B 社のテクノロジを組み込むことで新たなメリットを得るため、B 社を買収する手続きを進めています。
会社 A の情報セキュリティ マネージャーが主に注力すべき事項は次のどれですか。
正解:C
Company A's security architecture is the PRIMARY focus of Company A's information security manager, because it defines the overall security design and controls for the cloud services that Company A provides to its customers. The information security manager should ensure that the security architecture is aligned with the business objectives and requirements of Company A, and that it can accommodate the integration of Company B's technologies without compromising the security, performance, and availability of the cloud services.
Reference =
CISM Review Manual, 16th Edition, ISACA, 2020, p. 67: "Security architecture is the design of the security controls that are applied to the information assets and the relationships among those assets." CISM Review Manual, 16th Edition, ISACA, 2020, p. 68: "The information security manager should ensure that the security architecture is aligned with the enterprise's business objectives and requirements and supports the information security strategy and program." CISM Review Manual, 16th Edition, ISACA, 2020, p. 69: "The information security manager should consider the impact of changes in the enterprise environment, such as mergers and acquisitions, on the security architecture and identify the necessary modifications or enhancements to maintain the security posture of the enterprise."