16 ◾ Information Security Fundamentals
Before engaging in an arrangement for external data access (e.g., cloud solu-
tions and services), management must determine that there is a bona fide business
requirement for external parties to have access to the organization’s information
assets, or to begin use of a product and service provided by an external party.
Management must ensure it is aware of the security impacts of such an arrange-
ment before making such a decision, and a risk assessment should be conducted to
establish the implications and requirements associated with the potential relation-
ship. e risks associated with these arrangements need to be formally addressed
by the use of an acceptable risk assessment methodology. e purpos ...