ExamGecko
Question list
Search
Search

Question 629 - CISM discussion

Report
Export

An organization is planning to outsource network management to a service provider. Including which of the following in the contract would be the MOST effective way to mitigate information security risk?

A.
Requirement for regular information security awareness
Answers
A.
Requirement for regular information security awareness
B.
Right-to-audit clause
Answers
B.
Right-to-audit clause
C.
Service level agreement (SLA)
Answers
C.
Service level agreement (SLA)
D.
Requirement to comply with corporate security policy
Answers
D.
Requirement to comply with corporate security policy
Suggested answer: D

Explanation:

The most effective way to mitigate information security risk when outsourcing network management to a service provider is to include a requirement for the service provider to comply with the corporate security policy in the contract. This requirement ensures that the service provider follows the same security standards, procedures, and controls as the organization, and protects the confidentiality, integrity, and availability of the organization's data and systems. The requirement also defines the roles and responsibilities, the reporting and escalation mechanisms, and the penalties for non-compliance.

Reference=A Risk-Based Management Approach to Third-Party Data Security, Risk and Compliance,CISM Domain 2: Information Risk Management (IRM) [2022 update]

asked 01/10/2024
Mukesh Kumar
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first