QuestionQ1144
Information Security Risk ManagementWhen assessing vendors for sensitive-data processing, which action should be taken FIRST to ensure that the appropriate level of information security is provided?
- A Develop metrics for vendor performance.
- B Include information security criteria as part of vendor selection.
- C Review third-party reports of potential vendors.
- D Include information security clauses in the vendor contract.
Community Discussion