nerdexam
Isaca

CDPSE · Question #95

Which of the following provides the BEST assurance that a potential vendor is able to comply with privacy regulations and the organization's data privacy policy?

The correct answer is D. Conducting a risk assessment of all candidate vendors. Conducting a risk assessment of all candidate vendors provides the best assurance because it involves an independent, objective evaluation of each vendor's actual privacy practices, controls, and capabilities - rather than relying on the vendor's own claims. Options A (RFP…

Privacy Governance

Question

Which of the following provides the BEST assurance that a potential vendor is able to comply with privacy regulations and the organization's data privacy policy?

Options

  • AIncluding mandatory compliance language in the request for proposal (RFP)
  • BObtaining self-attestations from all candidate vendors
  • CRequiring candidate vendors to provide documentation of privacy processes
  • DConducting a risk assessment of all candidate vendors

How the community answered

(50 responses)
  • A
    32% (16)
  • B
    8% (4)
  • C
    12% (6)
  • D
    48% (24)

Explanation

Conducting a risk assessment of all candidate vendors provides the best assurance because it involves an independent, objective evaluation of each vendor's actual privacy practices, controls, and capabilities - rather than relying on the vendor's own claims. Options A (RFP compliance language), B (self-attestations), and C (documentation of privacy processes) all depend on information provided by the vendor itself, which may be incomplete, inaccurate, or unverifiable. A risk assessment allows the organization to independently validate vendor claims and identify gaps before entering into a relationship.

Topics

#Vendor management#Third-party risk management#Privacy assessment#Due diligence

Community Discussion

No community discussion yet for this question.

Full CDPSE Practice