Isaca Certified in Risk and Information Systems Control CRISC Question # 190 Topic 20 Discussion
CRISC Exam Topic 20 Question 190 Discussion:
Question #: 190
Topic #: 20
Which of the following provides a risk practitioner with the MOST reliable evidence of a third party's ability to protect the confidentiality of sensitive corporate information?
External audit reports are independent and objective, typically conducted under standard frameworks (e.g., SOC 2). They assess the third party’s controls in a structured and verifiable manner, offering the highest assurance of confidentiality protections.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit