ExamGecko
Question list
Search
Search

Question 626 - CISM discussion

Report
Export

An information security manager has become aware that a third-party provider is not in compliance with the statement of work (SOW). Which of the following is the BEST course of action?

A.
Notify senior management of the issue.
Answers
A.
Notify senior management of the issue.
B.
Report the issue to legal personnel.
Answers
B.
Report the issue to legal personnel.
C.
Initiate contract renegotiation.
Answers
C.
Initiate contract renegotiation.
D.
Assess the extent of the issue.
Answers
D.
Assess the extent of the issue.
Suggested answer: D

Explanation:

The first course of action when the information security manager becomes aware that a third-party provider is not in compliance with the SOW is to assess the extent of the issue, which means determining the nature, scope, and impact of the non-compliance on the security of the enterprise's data and systems. The assessment should also identify the root cause of the non-compliance and the possible remediation actions. The assessment will help the information security manager to decide the next steps, such as notifying senior management, reporting the issue to legal personnel, initiating contract renegotiation, or terminating the contract.

Reference=Ensuring Vendor Compliance and Third-Party Risk Mitigation,A Risk-Based Management Approach to Third-Party Data Security, Risk and Compliance

asked 01/10/2024
Jebaz Norton
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first