ExamGecko
Question list
Search
Search

Question 371 - CISM discussion

Report
Export

A finance department director has decided to outsource the organization's budget application and has identified potential providers. Which of the following actions should be initiated FIRST by IN information security manager?

A.
Determine the required security controls for the new solution
Answers
A.
Determine the required security controls for the new solution
B.
Review the disaster recovery plans (DRPs) of the providers
Answers
B.
Review the disaster recovery plans (DRPs) of the providers
C.
Obtain audit reports on the service providers' hosting environment
Answers
C.
Obtain audit reports on the service providers' hosting environment
D.
Align the roles of the organization's and the service providers' stats.
Answers
D.
Align the roles of the organization's and the service providers' stats.
Suggested answer: A

Explanation:

Before outsourcing any application or service, an information security manager should first determine the required security controls for the new solution, based on the organization's risk appetite, security policies and standards, and regulatory requirements. This will help to evaluate and select the most suitable provider, as well as to define the security roles and responsibilities, service level agreements (SLAs), and audit requirements.

Reference: https://www.isaca.org/credentialing/cism https://www.wiley.com/en-us/CISM+Certified+Information+Security+Manager+Study+Guide-p-9781119801948

asked 01/10/2024
Brian Kryszewski
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first