ExamGecko
Question list
Search
Search

Question 379 - CISM discussion

Report
Export

An organization has decided to outsource IT operations. Which of the following should be the PRIMARY focus of the information security manager?

A.
Security requirements are included in the vendor contract
Answers
A.
Security requirements are included in the vendor contract
B.
External security audit results are reviewed.
Answers
B.
External security audit results are reviewed.
C.
Service level agreements (SLAs) meet operational standards.
Answers
C.
Service level agreements (SLAs) meet operational standards.
D.
Business continuity contingency planning is provided
Answers
D.
Business continuity contingency planning is provided
Suggested answer: A

Explanation:

Security requirements are included in the vendor contract is the primary focus of the information security manager when outsourcing IT operations because it ensures that the vendor is legally bound to comply with the client's security policies and standards, as well as any external regulations or laws. This also helps to define the roles and responsibilities of both parties, the security metrics and controls to be used, and the penalties for non-compliance or breach. Therefore, security requirements are included in the vendor contract is the correct answer.

https://www.techtarget.com/searchsecurity/tip/15-benefits-of-outsourcing-your-cybersecurity-operations

https://www.sciencedirect.com/science/article/pii/S0378720616302166

asked 01/10/2024
Thiago B
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first