List of questions
Related questions
Question 17 - CCAK discussion
During an audit it was identified that a critical application hosted in an off-premises cloud is not part of the organization's DRP (Disaster Recovery Plan).
Management stated that it is responsible for ensuring that the cloud service provider (CSP) has a plan that is tested annually. What should be the auditor's NEXT course of action?
A.
Review the CSP audit reports.
B.
Review the security white paper of the CSP.
C.
Review the contract and DR capability.
D.
Plan an audit of the CSP.
Your answer:
0 comments
Sorted by
Leave a comment first