Certified Information Security Manager CISM · Free Practice Question Medium
Question 109
Achieving compliance of activities conducted by outsourcing providers with information security policies is MOST effectively accomplished by using:
- A A. Regular communication and training sessions with outsourcing providers
- B B. Independent audits
- C C. Strict contractual penalties for non-compliance
- D D. In-depth monitoring of outsourcing provider activities
Reveal correct answer
Correct answer: B
Explanation
Correct Answer: B. Independent audits Explanation: The most effective way to ensure compliance with information security policies for activities conducted by outsourcing providers is through independent audits. Independent audits provide an objective and thorough examination of the outsourcing provider's processes, controls, and adherence to security policies. This approach helps in identifying any non-compliance issues, verifying the effectiveness of security measures, and ensuring that the outsourcing provider meets the required standards. While communication, training, contractual penalties, and monitoring are valuable components, independent audits offer an impartial and comprehensive assessment of security compliance.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
