An enterprise has decided to procure security services from a third-party vendor to support its information security program. Which of the following is MOST important to include in the vendor selection criteria?
A.
The maturity of the vendor's internal control environment
B.
Feedback from the vendor's previous clients
C.
Alignment of the vendor's business objectives with enterprise security goals
D.
Penetration testing against the vendor's network
I answered C, but after looking up maturity models and realizing this was a case of answer written wrongly, I find A is the correct answer. C is written wrong "Alignment of the vendor's business objectives with enterprise security goals" Should be "Alignment of the vendor's security goals with Enterprise Business Objectives" Maturity of internal controls is highly important, look up maturity models. Could be me, but this seems to be the first quesiton that seemed like a trick question if you didnt properly read it. Please correct me if I am wrong.
C. Alignment of the vendor's business objectives with enterprise security goals
When selecting a third-party vendor to provide security services, it is crucial to ensure that their business objectives align with the enterprise's security goals. This alignment ensures that the vendor's services and solutions will effectively support the enterprise's information security program.
upvoted 2 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
fac161f
2 months, 2 weeks agosausageman
3 months, 1 week agobronay
6 months, 3 weeks agoshootnot
7 months agoyottabyte
7 months, 3 weeks agoJ3young
7 months, 4 weeks ago