QuestionQ43

Information System Auditing Process

When auditing a third-party provider, it is MOST important to ensure:

Explanation

A third-party audit should verify that risks identified in the risk assessment have been addressed through appropriate controls, mitigation, acceptance, or other risk-treatment actions. The other practices support ongoing vendor oversight but do not directly demonstrate that identified risks have been resolved.

Community Discussion

No comments yet. Be the first to start the discussion!