QuestionQ1144

Information Security Risk Management

When assessing vendors for sensitive-data processing, which action should be taken FIRST to ensure that the appropriate level of information security is provided?

  • A Develop metrics for vendor performance.
  • B Include information security criteria as part of vendor selection.
  • C Review third-party reports of potential vendors.
  • D Include information security clauses in the vendor contract.
Explanation

Information-security criteria should be included in the vendor-selection process so prospective vendors are evaluated against the required security level before a vendor is chosen. Contractual clauses and ongoing performance measures are applied after selection, while third-party reports are evidence considered within the evaluation.

Community Discussion

No comments yet. Be the first to start the discussion!