QuestionQ82

Information Security Risk Management

An information security manager has been asked to provide security-focused contract guidance for outsourcing the organization’s payroll processing. Which of the following is MOST important to address?

  • A Vendor compliance with the most stringent data security regulations
  • B Vendor compliance with the organization's information security policies
  • C Vendor compliance with organizational service level agreement (SLA) requirements
  • D Vendor compliance with recognized industry security standards
Explanation

A payroll-processing vendor must be contractually bound to the organization’s information security policies so that its handling of sensitive employee data meets the organization’s defined security requirements, risk tolerance, and applicable obligations. Third-party service providers should conform to the supported organization’s security policies and procedures.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!