Help with a question - Cloud

in CISA
An IS auditor is reviewing a third-party agreement for a new cloud-based accounting service provider. Which of the following considerations is the MOST important with regard to the privacy of the accounting data?
A. Data retention, backup and recovery
B. Return or destruction of information
C. Network and intrusion detection
D. A patch management process
Can you tell which is the correct answer and why? The option that I thought to be correct - A is wrong but I would like to hear from you. Data retention - data must be in encrypted format while at rest, backup and recovery also should be performed in a secured way with proper controls in place. Not quite getting why is this wrong.
Can you tell which is the correct answer and why? The option that I thought to be correct - A is wrong but I would like to hear from you. Data retention - data must be in encrypted format while at rest, backup and recovery also should be performed in a secured way with proper controls in place. Not quite getting why is this wrong.
---
With RegardsSumeet Gandhi
CISA, CISM, PMP, PMI-ACP, AWS Certified Solutions Architect, Office 365, SharePoint Online, SharePoint (2016 / 2013 / 2010 / 2007), MCTS, CSM, ITIL, PRINCE2
Tagged:
Comments
Thanks for the inputs, I am not very much convinced though, lets me give one example here. I create a new account on AWS or Azure and spin up VMs with 3 tier architecture. I then publish my own financial app on it and users are using. One day, I decide to move to something else. Now at this point I will go and terminate the instance. I loose all the VM's and database too. How will I guarantee that my data has been scrubbed off properly as I cannot ask them to send me the drive which has my data since its a shared environment nor I can visit them nor I can see with some proof that yes my data is gone for good.
Just trying to put the pieces together. Option B you mentioned is the correct one though.
Sumeet Gandhi
Sumeet Gandhi
Sumeet Gandhi