A chief Information Officer (CISO) is working with a consultant to perform a gap assessment prior to an upcoming audit. It is determined during the assessment that the organization lacks controls to effectively assess regulatory compliance by third-party service providers. Which of the following should be revised to address this gap? A. Privacy policy B. Work breakdown structure C. Interconnection security agreement D. Vendor management plan E. Audit report

Answered on

D. Vendor management plan

A Vendor Management Plan typically outlines the processes and controls for selecting, onboarding, and managing third-party service providers. By revising the Vendor Management Plan to include specific controls for assessing regulatory compliance by third-party service providers, the organization can better ensure that its vendors adhere to relevant regulations and standards.


Related Questions