nerdexam
(ISC)2

HCISPP · Question #283

Which of the following would BEST help a HCISPP determine if a third party has met an external attestation for information security or privacy?

The correct answer is A. ISO or SSAE No. 16 certifications. External attestation from recognized certification bodies like ISO or SSAE No. 16 (SOC reports) provides formal, auditor-verified proof that a third party meets defined security and privacy standards.

Third-Party Risk Management

Question

Which of the following would BEST help a HCISPP determine if a third party has met an external attestation for information security or privacy?

Options

  • AISO or SSAE No. 16 certifications
  • BLength of time vendor has been in business
  • CFinancial soundness
  • DPast performance reviews

How the community answered

(24 responses)
  • A
    79% (19)
  • B
    4% (1)
  • C
    13% (3)
  • D
    4% (1)

Why each option

External attestation from recognized certification bodies like ISO or SSAE No. 16 (SOC reports) provides formal, auditor-verified proof that a third party meets defined security and privacy standards.

AISO or SSAE No. 16 certificationsCorrect

ISO certifications (e.g., ISO/IEC 27001) and SSAE No. 16 (now SSAE 18) SOC reports are formal, independent third-party attestations that verify an organization has implemented and maintains specific information security or privacy controls. These are recognized industry standards specifically designed to communicate audit results about a vendor's control environment to relying parties.

BLength of time vendor has been in business

The length of time a vendor has been in business indicates market longevity but provides no evidence that the vendor meets any specific security or privacy control requirements.

CFinancial soundness

Financial soundness reflects economic stability but has no direct correlation to whether a vendor has implemented adequate information security or privacy controls.

DPast performance reviews

Past performance reviews are informal, retrospective assessments that lack the independent audit rigor required to constitute an external attestation of security or privacy compliance.

Concept tested: Third-party vendor external attestation and audit certifications

Source: https://www.aicpa.org/resources/landing/system-and-organization-controls-soc-suite-of-services

Topics

#Third-party risk management#Information security certifications#Privacy attestations#Compliance standards

Community Discussion

No community discussion yet for this question.

Full HCISPP Practice