IIA Business Knowledge for Internal Auditing IIA-CIA-Part3 Question # 7 Topic 1 Discussion
IIA-CIA-Part3 Exam Topic 1 Question 7 Discussion:
Question #: 7
Topic #: 1
According to IIA guidance, which of the following would be the best first step to manage risk when a third party is overseeing the organization’s network and data?
A.
Creating a comprehensive reporting system for vendors to demonstrate their ongoing due diligence in network operations
B.
Drafting a strong contract that requires regular vendor control reports and a right-to-audit clause
C.
Applying administrative privileges to ensure right-to-access controls are appropriate
D.
Creating a standing cybersecurity committee to identify and manage risks related to data security
[Reference: IIA Business Knowledge for Internal Auditing, Third-Party Risk Management section., , , ]
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit