nerdexam
CompTIA

CAS-003 · Question #475

A Chief Information Security Officer (CISO) is working with a consultant to perform a gap assessment prior to an upcoming audit. It is determined during the assessment that the organization lacks…

The correct answer is D. Vendor management plan. A Vendor Management Plan defines the organization's policies, procedures, and controls for managing third-party service providers, including how their regulatory compliance is assessed, monitored, and enforced. When a gap assessment reveals the organization cannot effectively…

Risk Management

Question

A Chief Information Security Officer (CISO) is working with a consultant to perform a gap assessment prior to an upcoming audit. It is determined during the assessment that the organization lacks controls to effectively assess regulatory compliance by third-party service providers. Which of the following should be revised to address this gap?

Options

  • APrivacy policy
  • BWork breakdown structure
  • CInterconnection security agreement
  • DVendor management plan
  • EAudit report

How the community answered

(40 responses)
  • A
    8% (3)
  • B
    3% (1)
  • C
    13% (5)
  • D
    75% (30)
  • E
    3% (1)

Explanation

A Vendor Management Plan defines the organization's policies, procedures, and controls for managing third-party service providers, including how their regulatory compliance is assessed, monitored, and enforced. When a gap assessment reveals the organization cannot effectively evaluate whether vendors meet compliance requirements, the Vendor Management Plan is the document that governs those oversight activities and must be updated to include compliance assessment controls. A privacy policy (A) governs how personal data is handled internally. A work breakdown structure (B) is a project management tool for decomposing project tasks. An interconnection security agreement (C) governs the security requirements for technical connections between systems of two organizations, not broader regulatory compliance oversight. An audit report (E) documents findings but is not a policy or control document.

Topics

#vendor management#third-party risk#compliance assessment#gap analysis

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice