ExamGecko
Question list
Search
Search

Question 59 - CISM discussion

Report
Export

When remote access to confidential information is granted to a vendor for analytic purposes, which of the following is the MOST important security consideration?

A.
Data is encrypted in transit and at rest at the vendor site.
Answers
A.
Data is encrypted in transit and at rest at the vendor site.
B.
Data is subject to regular access log review.
Answers
B.
Data is subject to regular access log review.
C.
The vendor must be able to amend data.
Answers
C.
The vendor must be able to amend data.
D.
The vendor must agree to the organization's information security policy,
Answers
D.
The vendor must agree to the organization's information security policy,
Suggested answer: D

Explanation:

When granting remote access to confidential information to a vendor, the most important security consideration is to ensure that the vendor complies with the organization's information security policy. The information security policy defines the roles, responsibilities, rules, and standards for accessing, handling, and protecting the organization's information assets. The vendor must agree to the policy and sign a contract that specifies the terms and conditions of the access, the security controls to be implemented, the monitoring and auditing mechanisms, the incident reporting and response procedures, and the penalties for non-compliance or breach. The policy also establishes the organization's right to revoke the access at any time if the vendor violates the policy or poses a risk to the organization.

Reference= CISM Review Manual, 16th Edition, Chapter 1: Information Security Governance, Section: Information Security Policies, page 34; CISM Review Questions, Answers & Explanations Manual, 10th Edition, Question 44, page 45.

asked 01/10/2024
Minh Phan
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first