Isaca Certified in Risk and Information Systems Control CRISC Question # 11 Topic 2 Discussion
CRISC Exam Topic 2 Question 11 Discussion:
Question #: 11
Topic #: 2
A Software as a Service (SaaS) provider has determined that the risk of a client's sensitive data being compromised is low. Which of the following is the client's BEST course of action?
A.
Implement additional controls to address the risk
B.
Accept the risk based on the provider's risk assessment
C.
Review the provider's independent audit results
D.
Ensure the contract includes breach notification requirements
Instead of relying solely on the provider’s internal assessment, the client should validate control effectiveness throughindependent audit reports(e.g., SOC 2 Type II). These provide third-party assurance.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit