IIA-CIA-Part3 Exam QuestionsBrowse all questions from this exam

IIA-CIA-Part3 Exam - Question 144


According to IIA guidance, which of the following would be the best first step to manage risk when a third party is overseeing the organization's network and data?

Show Answer
Correct Answer: BD

Drafting a strong contract that requires regular vendor control reports and a right-to-audit clause is the best initial step to manage risk when a third party oversees the organization's network and data. This ensures that the third party is contractually obligated to maintain specific security practices and allows the organization to verify compliance through audit rights. This proactive approach helps establish clear expectations and provides the means to monitor and enforce compliance, thereby mitigating risks associated with third-party oversight.

Discussion

4 comments
Sign in to comment
WalewweeeedOption: B
Jul 6, 2021

B is correct

KhetsOption: B
Nov 1, 2021

Correct answer is definitely B according to GTAG Assessing cyber security risk

ElvinOption: B
Feb 29, 2024

Why D? Should this be B?

KonradKOption: B
Mar 4, 2024

It's B!