List of questions
Related questions
Question 137 - CGEIT discussion
A healthcare enterprise that is subject to strict compliance requirements has decided to outsource several key IT services to third-party providers. Which of the following would be the BEST way to assess compliance and avoid reputational damage?
A.
Require quarterly reports from the providers demonstrating compliance.
B.
Require documentation that the providers have adequate controls in place.
C.
Exercise the right to perform an audit.
D.
Impose monetary penalties for noncompliance.
Your answer:
0 comments
Sorted by
Leave a comment first