An IT auditor for a bank is reviewing the institution's use of a public cloud service provider for hosting a critical customer-facing application. Which of the following is the MOST important consideration for the auditor when assessing the bank's risk management in this scenario?
-
A
The physical security of the cloud provider's data centers.
-
B
The bank's process for reviewing the cloud provider's SOC (Service Organization Control) reports.
-
C
The specific encryption algorithms used by the cloud provider for data at rest.
-
D
The cost-effectiveness of the cloud solution compared to an on-premise alternative.