List of questions
Related questions
Question 397 - CISM discussion
An information security team is planning a security assessment of an existing vendor. Which of the following approaches is MOST helpful for properly scoping the assessment?
A.
Focus the review on the infrastructure with the highest risk
B.
Review controls listed in the vendor contract
C.
Determine whether the vendor follows the selected security framework rules
D.
Review the vendor's security policy
Your answer:
0 comments
Sorted by
Leave a comment first