ExamGecko
Home Home / ISC / CCSP
Question list
Search
Search

Question 303 - CCSP discussion

Report
Export

During the course of an audit, which of the following would NOT be an input into the control requirements used as part of a gap analysis.

A.
Contractual requirements
Answers
A.
Contractual requirements
B.
Regulations
Answers
B.
Regulations
C.
Vendor recommendations
Answers
C.
Vendor recommendations
D.
Corporate policy
Answers
D.
Corporate policy
Suggested answer: C

Explanation:

Vendor recommendations would not be pertinent to the gap analysis after an audit. Although vendor recommendations will typically play a role in the development of corporate policies or contractual requirements, they are not required. Regulations, corporate policy, and contractual requirements all determine the expected or mandated controls in place on a system.

asked 18/09/2024
Luca Bombelli
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first