An organization engages a third-party vendor to monitor and support a financial application under scrutiny by regulators. Which of the following controls would MOST effectively manage risk to the organization?
A.
Implementing separation of duties between systems and data
B.
Including penalty clauses for noncompliance in the vendor contract
C.
Disabling vendor access and only re-enabling when access is needed
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit