CISM · Question #816
An outsourced vendor handles an organization's business-critical data. Which of the following is the MOST effective way for the client organization to obtain assurance of the vendor's security practic
The correct answer is D. Requiring periodic independent third-party reviews. Periodic independent third-party reviews (e.g., SOC 2 Type II audits, ISO 27001 certifications) provide objective, evidence-based assurance of the vendor's actual security controls - not just what the vendor claims. Vendor-provided disclosures (A) are self-reported and potentiall
Question
An outsourced vendor handles an organization's business-critical data. Which of the following is the MOST effective way for the client organization to obtain assurance of the vendor's security practices?
Options
- AReviewing recent information security disclosures from the vendor
- BReviewing the vendor service level agreement (SLA)
- CRequiring business continuity plans (BCPs) from the vendor
- DRequiring periodic independent third-party reviews
How the community answered
(23 responses)- A4% (1)
- B13% (3)
- C26% (6)
- D57% (13)
Explanation
Periodic independent third-party reviews (e.g., SOC 2 Type II audits, ISO 27001 certifications) provide objective, evidence-based assurance of the vendor's actual security controls - not just what the vendor claims. Vendor-provided disclosures (A) are self-reported and potentially biased. SLAs (B) define service targets but do not validate security control effectiveness. BCPs (C) address continuity but only cover one aspect of security. Independent reviews give the broadest, most credible assurance across all security domains.
Topics
Community Discussion
No community discussion yet for this question.