ExamGecko
Question list
Search
Search

Question 562 - CISM discussion

Report
Export

During the selection of a Software as a Service (SaaS) vendor for a business process, the vendor provides evidence of a globally accepted information security certification. Which of the following is the MOST important consideration?

A.
The certification includes industry-recognized security controls.
Answers
A.
The certification includes industry-recognized security controls.
B.
The certification was issued within the last five years.
Answers
B.
The certification was issued within the last five years.
C.
The certification is issued for the specific scope.
Answers
C.
The certification is issued for the specific scope.
D.
The certification is easily verified.
Answers
D.
The certification is easily verified.
Suggested answer: C

Explanation:

The most important consideration when selecting a SaaS vendor for a business process is whether the vendor's information security certification is issued for the specific scope of the service that the organization needs. A certification that covers the entire vendor organization or a different service may not be relevant or sufficient for the organization's security requirements. The certification should also include industry-recognized security controls, be issued within a reasonable time frame, and be easily verified, but these are not as critical as the scope.

Reference= CISM Review Manual, 16th Edition, page 1841; 5 Top SaaS Security Certifications for SaaS Providers

asked 01/10/2024
Melissa Petrini
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first