List of questions
Question 352 - CRISC discussion
Which of the following should a risk practitioner do FIRST when an organization decides to use a cloud service?
A.
Review the vendor selection process and vetting criteria.
B.
Assess whether use of service falls within risk tolerance thresholds.
C.
Establish service level agreements (SLAs) with the vendor.
D.
Check the contract for appropriate security risk and control provisions.
Your answer:
0 comments
Sorted by
Leave a comment first