QuestionQ811

Information Security Risk Management

To verify that a third-party provider meets an organization’s information-security requirements, it is MOST important to ensure:

  • A contract clauses comply with the organization's information security policy.
  • B security metrics are included in the service level agreement (SLA).
  • C the information security policy of the third-party service provider is reviewed.
  • D right to audit is included in the service level agreement (SLA).
Explanation

A right-to-audit provision gives the organization an enforceable means to examine evidence and assess a third-party provider’s actual, ongoing compliance with required security controls. NIST guidance requires monitoring external service providers’ security-requirement compliance on an ongoing basis; contractual requirements, provider policies, and SLA metrics establish expectations but do not by themselves provide verification.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!