ExamGecko
Question list
Search
Search

Related questions











Question 352 - CRISC discussion

Report
Export

Which of the following should a risk practitioner do FIRST when an organization decides to use a cloud service?

A.
Review the vendor selection process and vetting criteria.
Answers
A.
Review the vendor selection process and vetting criteria.
B.
Assess whether use of service falls within risk tolerance thresholds.
Answers
B.
Assess whether use of service falls within risk tolerance thresholds.
C.
Establish service level agreements (SLAs) with the vendor.
Answers
C.
Establish service level agreements (SLAs) with the vendor.
D.
Check the contract for appropriate security risk and control provisions.
Answers
D.
Check the contract for appropriate security risk and control provisions.
Suggested answer: D
asked 18/09/2024
janet phillips
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first