QuestionQ883

Information Security Risk Management

Which of the following is the BEST method for assessing the risk associated with using a Software as a Service (SaaS) vendor?

  • A Require vendors to complete information security questionnaires.
  • B Request customer references from the vendor.
  • C Verify that information security requirements are included in the contract.
  • D Review the results of the vendor's independent control reports.
Explanation

Independent control reports provide objective, third-party evidence of a SaaS vendor’s control environment and, where applicable, the operating effectiveness of those controls. This offers more reliable assurance than vendor-completed questionnaires, customer references, or merely confirming that security requirements appear in a contract.

Community Discussion

No comments yet. Be the first to start the discussion!