ExamGecko
Question list
Search
Search

Question 450 - CISM discussion

Report
Export

What is the role of the information security manager in finalizing contract negotiations with service providers?

A.
To perform a risk analysis on the outsourcing process
Answers
A.
To perform a risk analysis on the outsourcing process
B.
To obtain a security standard certification from the provider
Answers
B.
To obtain a security standard certification from the provider
C.
To update security standards for the outsourced process
Answers
C.
To update security standards for the outsourced process
D.
To ensure that clauses for periodic audits are included
Answers
D.
To ensure that clauses for periodic audits are included
Suggested answer: A

Explanation:

The role of the information security manager in finalizing contract negotiations with service providers is to ensure that the outsourcing process is aligned with the organization's information security policies, standards, and objectives. One of the key aspects of this process is to perform a risk analysis on the outsourcing process, which involves identifying, assessing, and mitigating the potential threats and vulnerabilities that may arise from outsourcing activities. A risk analysis can help the information security manager to determine the appropriate level of security controls and requirements for the outsourced process, as well as to monitor and evaluate its performance and compliance.A risk analysis can also help to avoid or minimize legal, financial, reputational, or operational risks associated with outsourcing1.Reference=

CISM Review Manual (Digital Version), Chapter 6: Information Security Program Management

CISM Review Manual (Print Version), Chapter 6: Information Security Program Management

asked 01/10/2024
Daniel Ramirez
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first