CISM · Question #478
Which of the following is the BEST method for minimizing the risk of noncompliance to security requirements by a third-party service provider?
The correct answer is B. Periodic reviews. The best method for minimizing the risk of noncompliance by a third-party service provider is to conduct periodic reviews. These reviews help ensure that the provider continues to meet security requirements, contractual obligations, and regulatory standards over time. While…
Question
Which of the following is the BEST method for minimizing the risk of noncompliance to security requirements by a third-party service provider?
Options
- AUnderstanding the third-party security programs
- BPeriodic reviews
- CBusiness impact analysis (BIA)
- DClear communication of security requirements
How the community answered
(21 responses)- A10% (2)
- B62% (13)
- C24% (5)
- D5% (1)
Explanation
The best method for minimizing the risk of noncompliance by a third-party service provider is to conduct periodic reviews. These reviews help ensure that the provider continues to meet security requirements, contractual obligations, and regulatory standards over time. While understanding their security programs and communicating requirements are important, ongoing reviews provide proactive assurance that controls are maintained and risks are managed effectively. A BIA focuses on business impact rather than compliance enforcement.
Topics
Community Discussion
No community discussion yet for this question.