QuestionQ328
Risk AssessmentWhich of the following would pose the GREATEST risk when the processing of personally identifiable information (PII) is outsourced to a vendor that uses subcontractors?
- A The vendor's service level agreements (SLAs) are not defined.
- B There have been no recent onsite visits to the vendor.
- C The vendor does not have a third-party risk management program.
- D The contract lacks a right-to-audit clause.
Community Discussion