ExamGecko
Question list
Search
Search

Question 652 - CISM discussion

Report
Export

An organization is considering using a third party to host sensitive archived data. Which of the following is MOST important to verify before entering into the relationship?

A.
The vendor's data centers are in the same geographic region.
Answers
A.
The vendor's data centers are in the same geographic region.
B.
The encryption keys are not provisled to the vendor.
Answers
B.
The encryption keys are not provisled to the vendor.
C.
The vendor's controls are in line with the organization's security standards.
Answers
C.
The vendor's controls are in line with the organization's security standards.
D.
Independent audits of the vendor's operations are regularly conducted.
Answers
D.
Independent audits of the vendor's operations are regularly conducted.
Suggested answer: C

Explanation:

The most important thing to verify before entering into a relationship with a third party to host sensitive archived data isthe vendor's controls are in line with the organization's security standards. This is because the organization is ultimately responsible for the security and privacy of its data, even if it is stored or processed by a third party. The organization should ensure that the vendor has adequate and effective controls to protect the data from unauthorized access, modification, disclosure, or destruction. The organization should also ensure that the vendor complies with the applicable laws and regulations regarding data protection, such as the General Data Protection Regulation (GDPR) in the European Union. The organization should conduct a thorough risk assessment of the vendor and its services, and establish a clear contract that defines the roles, responsibilities, expectations, and obligations of both parties.

Reference= CISM Review Manual 15th Edition, Chapter 3, Section 3.2.1, page 1341; CISM Review Questions, Answers & Explanations Manual 9th Edition, Question 2, page 2

asked 01/10/2024
Cynan Jones
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first