Certified Information Security Manager CISM · Free Practice Question Medium

Question 109

Achieving compliance of activities conducted by outsourcing providers with information security policies is MOST effectively accomplished by using:
  • A A. Regular communication and training sessions with outsourcing providers
  • B B. Independent audits
  • C C. Strict contractual penalties for non-compliance
  • D D. In-depth monitoring of outsourcing provider activities
Reveal correct answer

Correct answer: B

Explanation

Correct Answer: B. Independent audits Explanation: The most effective way to ensure compliance with information security policies for activities conducted by outsourcing providers is through independent audits. Independent audits provide an objective and thorough examination of the outsourcing provider's processes, controls, and adherence to security policies. This approach helps in identifying any non-compliance issues, verifying the effectiveness of security measures, and ensuring that the outsourcing provider meets the required standards. While communication, training, contractual penalties, and monitoring are valuable components, independent audits offer an impartial and comprehensive assessment of security compliance.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need