ExamGecko
Question list
Search
Search

Question 589 - CISM discussion

Report
Export

An organization learns that a third party has outsourced critical functions to another external provider. Which of the following is the information security manager's MOST important course of action?

A.
Engage an independent audit of the third party's external provider.
Answers
A.
Engage an independent audit of the third party's external provider.
B.
Recommend canceling the contract with the third party.
Answers
B.
Recommend canceling the contract with the third party.
C.
Evaluate the third party's agreements with its external provider.
Answers
C.
Evaluate the third party's agreements with its external provider.
D.
Conduct an external audit of the contracted third party.
Answers
D.
Conduct an external audit of the contracted third party.
Suggested answer: C

Explanation:

According to the CISM Review Manual, the information security manager should evaluate the third party's agreements with its external provider to ensure that the security requirements and controls are adequate and consistent with the organization's expectations. Engaging or conducting an audit may be a subsequent step, but not the most important one. Recommending canceling the contract may be premature and impractical.

Reference= CISM Review Manual, 27th Edition, Chapter 3, Section 3.4.2, page 1431.

asked 01/10/2024
NAKAYAMA HIROYUKI
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first