QuestionQ811
Information Security Risk ManagementTo verify that a third-party provider meets an organization’s information-security requirements, it is MOST important to ensure:
- A contract clauses comply with the organization's information security policy.
- B security metrics are included in the service level agreement (SLA).
- C the information security policy of the third-party service provider is reviewed.
- D right to audit is included in the service level agreement (SLA).
Community Discussion