CISM · Question #798
An information security manager learns that an existing supplier plans to begin using its recently developed generative AI technology for the same scope of service. A risk assessment was performed…
The correct answer is A. Suspend the use of the supplier until a risk assessment of the AI technology has been performed. Generative AI introduces new risks (e.g., data leakage, model poisoning). These risks were not part of the original assessment, so a fresh risk assessment must be conducted before continuing "When a significant change in third-party operations occurs, it necessitates a…
Question
An information security manager learns that an existing supplier plans to begin using its recently developed generative AI technology for the same scope of service. A risk assessment was performed on the supplier three months ago with no outstanding findings. Which of the following is the BEST course of action to address the associated risk?
Options
- ASuspend the use of the supplier until a risk assessment of the AI technology has been performed
- BReport the change in risk to senior management
- CReview the results of the previous risk assessment
- DAdd an indemnity clause in the contractual agreement at the renewal stage
How the community answered
(59 responses)- A64% (38)
- B10% (6)
- C5% (3)
- D20% (12)
Explanation
Generative AI introduces new risks (e.g., data leakage, model poisoning). These risks were not part of the original assessment, so a fresh risk assessment must be conducted before continuing "When a significant change in third-party operations occurs, it necessitates a reassessment of risk before continuing operations." This ensures security, compliance, and operational continuity.
Topics
Community Discussion
No community discussion yet for this question.