ExamGecko
Question list
Search
Search

Related questions











Question 515 - CISA discussion

Report
Export

Which of the following should be the FIRST step when planning an IS audit of a third-party service provider that monitors network activities?

A.
Review the third party's monitoring logs and incident handling
Answers
A.
Review the third party's monitoring logs and incident handling
B.
Review the roles and responsibilities of the third-party provider
Answers
B.
Review the roles and responsibilities of the third-party provider
C.
Evaluate the organization's third-party monitoring process
Answers
C.
Evaluate the organization's third-party monitoring process
D.
Determine if the organization has a secure connection to the provider
Answers
D.
Determine if the organization has a secure connection to the provider
Suggested answer: B

Explanation:

The first step when planning an IS audit of a third-party service provider that monitors network activities is to review the roles and responsibilities of the third-party provider. This will help to establish the scope, objectives, and expectations of the audit, as well as to identify any potential risks, issues, or gaps in the service level agreement (SLA) between the organization and the provider.Reviewing the third party's monitoring logs and incident handling, evaluating the organization's third-party monitoring process, and determining if the organization has a secure connection to the provider are important steps, but they should be performed after reviewing the roles and responsibilities of the provider.Reference:CISA Review Manual (Digital Version)1, page 269.

asked 18/09/2024
Chris Abunin
28 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first