CISM · Question #864
An information security manager has identified that a third-party Software as a Service (SaaS) provider is not compliant with privacy regulations. Which of the following is the BEST course of action?
The correct answer is A. Determine the impact of noncompliance.. The best first course of action is to determine the business, legal, and regulatory impact of the provider’s noncompliance. This establishes severity and urgency and drives the appropriate response (e.g., require remediation, apply contractual remedies, implement compensating con
Question
An information security manager has identified that a third-party Software as a Service (SaaS) provider is not compliant with privacy regulations. Which of the following is the BEST course of action?
Options
- ADetermine the impact of noncompliance.
- BAsk the contractor to resolve the identified issues.
- CActivate contractual noncompliance penalties.
- DImplement temporary compensating controls.
How the community answered
(47 responses)- A81% (38)
- B2% (1)
- C6% (3)
- D11% (5)
Explanation
The best first course of action is to determine the business, legal, and regulatory impact of the provider’s noncompliance. This establishes severity and urgency and drives the appropriate response (e.g., require remediation, apply contractual remedies, implement compensating controls, or exit the relationship).
Topics
Community Discussion
No community discussion yet for this question.