ExamGecko
Question list
Search
Search

Question 547 - CISM discussion

Report
Export

Which of the following elements of a service contract would BEST enable an organization to monitor the information security risk associated with a cloud service provider?

A.
Indemnification clause
Answers
A.
Indemnification clause
B.
Breach detection and notification
Answers
B.
Breach detection and notification
C.
Compliance status reporting
Answers
C.
Compliance status reporting
D.
Physical access to service provider premises
Answers
D.
Physical access to service provider premises
Suggested answer: C

Explanation:

Compliance status reporting is the best element of a service contract that would enable an organization to monitor the information security risk associated with a cloud service provider, as it provides the organization with regular and timely information on the cloud service provider's compliance with the agreed-upon security requirements, standards, and regulations. Compliance status reporting also helps the organization to identify any gaps or issues that need to be addressed or resolved, and to verify the effectiveness of the cloud service provider's controls. (From CISM Review Manual 15th Edition)

asked 01/10/2024
Lionel Fitzgerald Gweth
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first