CISM Exam QuestionsBrowse all questions from this exam

CISM Exam - Question 1095


An organization learns that a third party has outsourced critical functions to another external provider. Which of the following is the information security manager's MOST important course of action?

Show Answer
Correct Answer: D

The most important course of action for the information security manager is to evaluate the third party's agreements with its external provider. This evaluation ensures that the necessary security controls and safeguards are in place to mitigate risks associated with outsourcing critical functions. It is essential to understand the terms, responsibilities, and security measures outlined in these agreements to ensure they align with the organization's security requirements.

Discussion

1 comment
Sign in to comment
BooictOption: D
Jul 17, 2024

D - This evaluation ensures that the necessary security controls and safeguards are in place to mitigate risks associated with outsourcing.