Related questions
Question 89 - IIA-CIA-Part3 discussion
An organization is considering outsourcing its IT services, and the internal auditor as assessing the related risks. The auditor grouped the related risks into three categories;
- Risks specific to the organization itself.
- Risks specific to the service provider.
- Risks shared by both the organization and the service provider
Which of the following risks should the auditor classify as specific to the service provider?
A.
Unexpected increases in outsourcing costs.
B.
Loss of data privacy.
C.
Inadequate staffing.
D.
Violation of contractual terms.
Your answer:
0 comments
Sorted by
Leave a comment first