712-50 Question 19
Single answerA multinational healthcare company headquartered in Germany plans to migrate a patient engagement platform to a public cloud provider. The platform will store EU patient personal data, and the provider has primary hosting in Ireland with automated failover to the United States and support operations performed from India. During contract review, the CIO states that because the cloud provider is ISO 27001 certified and offers a standard data processing addendum, the company can proceed without major policy changes. As the CISO, what is the MOST appropriate action to address the legal and jurisdictional risks before migration?
- A
Approve the migration because the provider's ISO 27001 certification demonstrates legal compliance across all involved jurisdictions.
- B
Require the organization to perform a data transfer impact assessment, define data residency and cross-border transfer requirements in policy, and update contractual controls to address processor/subprocessor locations, government access requests, and breach notification obligations.
- C
Rely on the cloud provider's shared responsibility model documentation and transfer legal accountability for privacy compliance to the provider through the master service agreement.
- D
Proceed with the migration if encryption is enabled for data at rest and in transit, since encrypted data is generally exempt from jurisdictional and regulatory concerns.
Show answer and explanation
Correct answer: B
Explanation
In cloud computing, legal and jurisdictional risk extends beyond the physical hosting location to include backup sites, support access, subprocessors, and compelled disclosure regimes. For a German healthcare company handling EU patient data, the organization must evaluate GDPR-related cross-border transfer implications and ensure appropriate governance before migration. Key best practices include conducting a transfer impact assessment where relevant, documenting data residency and transfer requirements in internal policy, validating subprocessor and support location disclosures, and embedding contractual controls for breach notification, audit rights, data return/deletion, and handling of government access requests. This aligns with widely accepted guidance from the CSA Cloud Controls Matrix, ISO/IEC 27018 for protection of PII in public clouds, and regulatory expectations under EU data protection frameworks. The core CCISO principle tested here is that cloud adoption does not remove the organization's responsibility to establish policies, assess jurisdictional exposure, and implement enforceable contractual and governance controls.
- A. Incorrect.
Incorrect. ISO 27001 certification indicates that the provider has an information security management system, but it does not by itself establish compliance with all privacy, data transfer, healthcare, or jurisdiction-specific legal requirements. A common misconception is to treat security certification as a substitute for legal due diligence. Certifications help assess control maturity, but the customer organization remains responsible for understanding where data is stored, accessed, and transferred, and for ensuring lawful processing and transfer mechanisms.
- B. Correct.
Correct. This is the most appropriate executive action because it addresses both jurisdictional exposure and the organization's governance responsibilities. In this scenario, EU personal data may be accessed or transferred outside the EU/EEA due to U.S. failover and Indian support operations. The organization should assess cross-border transfer risks, define policy requirements for residency and transfer restrictions, and ensure the contract covers processor and subprocessor transparency, legal request handling, breach notification timing, audit rights, and regulatory obligations. This reflects the organization's responsibility in a cloud model: the provider may operate the infrastructure, but the customer retains accountability for compliance and policy enforcement.
- C. Incorrect.
Incorrect. The shared responsibility model allocates operational security responsibilities, but it does not transfer legal accountability for the organization's regulated data processing. Organizations cannot contract away core compliance obligations simply by relying on provider documentation or standard contract language. This option reflects a frequent governance error: confusing outsourced operations with outsourced accountability.
- D. Incorrect.
Incorrect. Encryption is an important safeguard, but it does not eliminate legal and jurisdictional implications. Regulators still consider issues such as where data is processed, who can access keys, lawful transfer mechanisms, subprocessor access, discovery obligations, and government disclosure demands. Encryption reduces risk; it does not make jurisdictional requirements disappear.