Master cloud strategy and architecture governance. Train your ability to correctly classify complex enterprise deployment models to ensure proper regulatory and risk management frameworks are applied.
You are the CISO of OmniMart Global, a multinational retail enterprise. To prepare for unprecedented holiday e-commerce traffic, the CIO proposes a digital transformation initiative. The strategy involves bursting customer-facing web traffic into a third-party managed environment (like AWS or Azure) while keeping the core transaction and customer PII databases strictly within OmniMart's wholly-owned, on-premise data centers.
OmniMart must maintain strict PCI-DSS and GDPR compliance. Moving sensitive PII entirely to a shared, multi-tenant environment exceeds the Board's risk appetite regarding data sovereignty and unauthorized access.
The business requires infinite, elastic scalability for the frontend during peak seasons to prevent revenue loss. However, authorizing the massive Capital Expenditure (CapEx) to build physical on-premise servers for a 3-week peak season is financially unviable.
The Board of Directors is reviewing the proposed architecture: a model where the frontend and backend remain physically distinct but are securely bound together via proprietary APIs and an encrypted IPsec VPN tunnel, allowing seamless data sharing. The Risk Committee requires you to formally classify this operating model so the correct audit and governance framework can be mandated.
The organization must balance the business demand for rapid, elastic scale with the security mandate for strict data sovereignty and regulatory compliance. Achieving both requires a complex, multi-environment architecture.
The business seeks the massive cost-efficiency and elasticity of the public cloud. Security and legal teams demand the isolation and total control of a private cloud. A blended approach bridges this gap, but exponentially increases governance complexity across the interconnect.
Adopting this architecture introduces significant risk at the integration layer. The APIs and VPN tunnels connecting the private and public spheres become the new primary attack surface, requiring unified identity and access management (IAM) and strict data loss prevention (DLP) across both environments.
(D) Hybrid cloud is the BEST answer because it is the exact technical and governance definition of an architecture combining two distinct infrastructures (public and private). They remain unique entities but are bound by standardized or proprietary technology that enables data and application portability.
Managing the Seams: Moving to a Hybrid Cloud means you operate in a shared responsibility model (public) and a wholly-owned responsibility model (private) simultaneously. Governance must establish clear data classification policies that dictate exactly which workloads belong in which environment. The greatest risk in a hybrid cloud is a misconfiguration at the "seam" where the two clouds meet.
Continue testing your strategic governance skills with more CCISO scenarios.
Explore more CCISO simulations