QuestionQ1803

Risk Response and Reporting

Which of the following is the BEST method to mitigate the risk of third-party cloud service personnel gaining inappropriate access to personally identifiable information (PII)?

  • A Utilize data encryption standards throughout the information life cycle
  • B Ensure security clearance is in place within the third-party hiring process
  • C Choose a third-party provider in a jurisdiction with few privacy regulations
  • D Include data security requirements in the service level agreement (SLA)
Explanation

Including data-security requirements in the service level agreement (SLA) creates binding obligations for the provider to implement and maintain controls over its personnel’s access to PII, such as least-privilege access, monitoring, screening, auditing, and incident-response requirements.

Community Discussion

No comments yet. Be the first to start the discussion!