QuestionQ695

Information Security Risk Management

When a vendor is granted remote access to confidential information for analytical purposes, which of the following is the MOST important security consideration?

  • A The vendor must be able to amend data
  • B The vendor must agree to the organization's information security policy
  • C Data is encrypted in transit and at rest at the vendor site
  • D Data is subject to regular access log review
Explanation

A vendor with remote access to confidential information must formally agree to comply with the organization’s information security policy. This establishes the vendor’s responsibility to meet the organization’s security requirements, including relevant technical and operational controls.

Community Discussion

No comments yet. Be the first to start the discussion!