nerdexam
Isaca

CISM · Question #864

An information security manager has identified that a third-party Software as a Service (SaaS) provider is not compliant with privacy regulations. Which of the following is the BEST course of action?

The correct answer is A. Determine the impact of noncompliance.. The best first course of action is to determine the business, legal, and regulatory impact of the provider’s noncompliance. This establishes severity and urgency and drives the appropriate response (e.g., require remediation, apply contractual remedies, implement compensating con

Submitted by manish99· Apr 18, 2026Information Security Risk Management

Question

An information security manager has identified that a third-party Software as a Service (SaaS) provider is not compliant with privacy regulations. Which of the following is the BEST course of action?

Options

  • ADetermine the impact of noncompliance.
  • BAsk the contractor to resolve the identified issues.
  • CActivate contractual noncompliance penalties.
  • DImplement temporary compensating controls.

How the community answered

(47 responses)
  • A
    81% (38)
  • B
    2% (1)
  • C
    6% (3)
  • D
    11% (5)

Explanation

The best first course of action is to determine the business, legal, and regulatory impact of the provider’s noncompliance. This establishes severity and urgency and drives the appropriate response (e.g., require remediation, apply contractual remedies, implement compensating controls, or exit the relationship).

Topics

#Risk assessment#Compliance management#Third-party risk#Privacy regulations

Community Discussion

No community discussion yet for this question.

Full CISM Practice