QuestionQ116

Privacy Risk Management and Compliance

Which of the following offers the BEST assurance that a prospective vendor can comply with privacy regulations and the organization’s data privacy policy?

  • A Including mandatory compliance language in the request for proposal (RFP)
  • B Conducting a risk assessment of all candidate vendors
  • C Requiring candidate vendors to provide documentation of privacy processes
  • D Obtaining self-attestations from all candidate vendors
Explanation

A risk assessment independently evaluates a candidate vendor’s privacy risks and relevant controls against regulatory obligations and the organization’s privacy-policy requirements. This provides stronger assurance than contractual language, supplied documentation, or an unverified self-attestation.

Community Discussion

No comments yet. Be the first to start the discussion!