Isaca
CISM · Question #921
Which of the following is MOST important for an information security manager to verify when selecting a third-party forensics provider?
The correct answer is C. Existence of a right-to-audit clause. The MOST important factor is the organization’s ability to verify, oversee, and legally rely on the provider’s work. A right-to-audit clause ensures chain-of-custody assurance, regulatory defensibility, and contractual accountability.
Submitted by yasin.bd· Apr 18, 2026Information Security Governance
Question
Which of the following is MOST important for an information security manager to verify when selecting a third-party forensics provider?
Options
- AExistence of the provider's incident response plan
- BResults of the provider's business continuity tests
- CExistence of a right-to-audit clause
- DTechnical capabilities of the provider
How the community answered
(16 responses)- A13% (2)
- B6% (1)
- C75% (12)
- D6% (1)
Explanation
The MOST important factor is the organization’s ability to verify, oversee, and legally rely on the provider’s work. A right-to-audit clause ensures chain-of-custody assurance, regulatory defensibility, and contractual accountability.
Topics
#Third-party risk management#Vendor oversight#Right-to-audit clause#Forensic provider selection
Community Discussion
No community discussion yet for this question.