QuestionQ380

Risk Response and Reporting

A trusted third-party service provider has concluded that the risk of a client’s systems being hacked is low. What is the client’s BEST course of action?

  • A Perform an independent audit of the third party.
  • B Accept the risk based on the third party's risk assessment.
  • C Perform their own risk assessment.
  • D Implement additional controls to address the risk.
Explanation

The client remains responsible for managing risk to its own systems. A third-party assessment is useful input, but the client should perform its own risk assessment to validate the risk in the context of its environment, assets, requirements, and existing controls.

Community Discussion

No comments yet. Be the first to start the discussion!