CISM · Question #300
Which of the following is the MOST effective method to ensure organizations have adequate security controls over outsourced services?
The correct answer is C. Require regular security compliance audits by an agreed.to independent third party. Contractual requirements and policy mandates (Choices B and D) establish what the provider should do but offer no independent verification that they actually do it. Regular reviews of the provider's own policies (Choice A) are self-assessed and lack objectivity. Independent…
Question
Which of the following is the MOST effective method to ensure organizations have adequate security controls over outsourced services?
Options
- ARequire regular reviews of the service provider's security policies and processes.
- BRequire a signed contract obliging the service provider to implement industry best practices.
- CRequire regular security compliance audits by an agreed.to independent third party.
- DRequire the service provider to use the organization's security policies and standards.
How the community answered
(48 responses)- A17% (8)
- B4% (2)
- C67% (32)
- D13% (6)
Explanation
Contractual requirements and policy mandates (Choices B and D) establish what the provider should do but offer no independent verification that they actually do it. Regular reviews of the provider's own policies (Choice A) are self-assessed and lack objectivity. Independent third-party compliance audits provide objective, evidence-based verification that security controls are actually implemented and operating effectively. Because the auditor has no stake in the outcome, findings are credible and actionable. This is the most effective method because it closes the gap between what is promised and what is practiced.
Topics
Community Discussion
No community discussion yet for this question.