nerdexam
IIA

IIA-CIA-PART2 · Question #450

Which of the following steps should an internal auditor complete when conducting a review of an electronic data interchange application provided by a third-party service? 1. Ensure encryption keys…

The correct answer is C. 2 and 3. When conducting a review of an electronic data interchange (EDI) application provided by a third- party service, it is essential to determine whether an independent review of the service provider's operation has been conducted and to verify that the service provider's contracts…

Performing the Engagement

Question

Which of the following steps should an internal auditor complete when conducting a review of an electronic data interchange application provided by a third-party service? 1. Ensure encryption keys meet ISO standards. 2. Determine whether an independent review of the service provider's operation has been conducted. 3. Verify that the service provider's contracts include necessary clauses. 4. Verify that only public-switched data networks are used by the service provider.

Options

  • A1 and 3.
  • B1 and 4.
  • C2 and 3.
  • D2 and 4.

How the community answered

(41 responses)
  • A
    15% (6)
  • B
    7% (3)
  • C
    76% (31)
  • D
    2% (1)

Explanation

When conducting a review of an electronic data interchange (EDI) application provided by a third- party service, it is essential to determine whether an independent review of the service provider's operation has been conducted and to verify that the service provider's contracts include necessary clauses. These steps ensure that the service provider operates securely and meets the organization's requirements for data protection and service reliability.

Topics

#electronic data interchange#third-party service provider#service provider contracts#independent review

Community Discussion

No community discussion yet for this question.

Full IIA-CIA-PART2 Practice