nerdexam
Isaca

CDPSE · Question #146

Which of the following is the BEST way to ensure privacy considerations are included when working with vendors?

The correct answer is C. Including privacy requirements in vendor contracts. Including privacy requirements in vendor contracts is the best control because contracts are legally binding and enforceable. They create formal, documented obligations that vendors must comply with, and provide recourse if they fail to do so. An RFP (A) sets expectations…

Privacy Governance

Question

Which of the following is the BEST way to ensure privacy considerations are included when working with vendors?

Options

  • AIncluding privacy requirements in the request for proposal (RFP) process
  • BMonitoring privacy-related service level agreements (SLAS)
  • CIncluding privacy requirements in vendor contracts
  • DRequiring vendors to complete privacy awareness training

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    91% (30)

Explanation

Including privacy requirements in vendor contracts is the best control because contracts are legally binding and enforceable. They create formal, documented obligations that vendors must comply with, and provide recourse if they fail to do so. An RFP (A) sets expectations before engagement but is not binding once a vendor is selected. Monitoring SLAs (B) is reactive oversight after the fact. Privacy awareness training (D) builds knowledge but does not create a legal obligation or enforceable standard. Only the contract creates a durable, enforceable privacy commitment.

Topics

#Vendor Management#Third-Party Risk Management#Privacy Contracts#Legal Requirements

Community Discussion

No community discussion yet for this question.

Full CDPSE Practice