CGEIT · Question #653
Which of the following would BEST enable an enterprise to ensure selected cloud vendors meet stringent regulatory requirements?
The correct answer is D. Third-party audit reports. To ensure cloud vendors meet stringent regulatory requirements, obtaining third-party audit reports (e.g., SOC 2, ISO 27001) is the best method as they provide independent verification of a vendor's controls.
Question
Which of the following would BEST enable an enterprise to ensure selected cloud vendors meet stringent regulatory requirements?
Options
- AStage gate reviews
- BRisk assessment
- CInternal audit report
- DThird-party audit reports
How the community answered
(46 responses)- A9% (4)
- B17% (8)
- C4% (2)
- D70% (32)
Why each option
To ensure cloud vendors meet stringent regulatory requirements, obtaining third-party audit reports (e.g., SOC 2, ISO 27001) is the best method as they provide independent verification of a vendor's controls.
Stage gate reviews are internal project management checkpoints and are not specifically designed to assess a vendor's ongoing regulatory compliance.
While a risk assessment is crucial for understanding potential vendor risks, it is an internal process and may not provide the independent, comprehensive evidence of regulatory compliance that a third-party audit report offers.
An internal audit report of the enterprise itself would assess the enterprise's controls over vendor management, but it would not provide direct evidence of the *vendor's* adherence to regulatory requirements.
Third-party audit reports (such as SOC 2, ISO 27001, or FedRAMP assessments) provide independent verification and assurance that a cloud vendor's security, compliance, and operational controls meet stringent regulatory and industry standards. These reports offer an objective and comprehensive view of the vendor's adherence to required controls, making them the best tool for ensuring compliance.
Concept tested: Cloud vendor due diligence for compliance
Source: https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2
Topics
Community Discussion
No community discussion yet for this question.