Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 1718 discussion

Actual exam question from Isaca's CISA
Question #: 1718
Topic #: 1
[All CISA Questions]

An IS auditor is reviewing the contract for a customer relationship management (CRM) system containing personal identifiable information (PII) hosted by a third party. The absence of which of the following would be the GREATEST concern regarding the contract?

  • A. Right-to-audit clause
  • B. Service level agreements (SLAs)
  • C. System availability requirements
  • D. Confidentiality terms
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Enig
2 days, 13 hours ago
A. Right-to-audit clause The absence of a right-to-audit clause would be the greatest concern in this scenario. This clause allows the organization to review and verify the third party’s compliance with security, privacy, and data protection requirements, especially important for a CRM system that contains personally identifiable information (PII). Without a right-to-audit clause, the organization may have limited ability to assess whether the third party is adequately protecting PII, which could increase risks related to data breaches and regulatory non-compliance. While SLAs, availability requirements, and confidentiality terms are also important, the right-to-audit clause is critical for ensuring ongoing compliance and accountability.
upvoted 1 times
...
blehbleh
3 weeks, 4 days ago
Selected Answer: D
D is the correct answer. We care about the PII and the confidentiality terms which covers what is whos responsibility, to what level it needs to be protected and other things. Just because you have a right to audit clause does not mean that it meets the required standards, policies, or procedures necessary for your data that they are handling.
upvoted 3 times
...
thusharaj
1 month, 3 weeks ago
A right-to-audit clause allows the organisation to assess the third party's security controls, compliance with legal requirements, and handling of sensitive data like PII. Without this clause, the organisation cannot verify if the third party is properly protecting PII, which could expose the organisation to legal and compliance risks.
upvoted 1 times
...
PurpleParrot
1 month, 3 weeks ago
Selected Answer: A
Option A because it is more comprehensive A right-to-audit clause is critical because it gives the client organization the contractual right to audit the vendor’s security controls, processes, and compliance. Without this, the client would have no way to verify that the vendor is properly securing the sensitive personal identifiable information (PII) as required. Confidentiality terms prohibit the vendor from disclosing data but don’t give the client the right to audit the vendor’s practices. Therefore, the absence of a right-to-audit clause would be the most concerning for an IS auditor reviewing this contract, as it removes the client’s ability to verify the vendor’s security and compliance through an audit. The right-to-audit is an essential safeguard for sensitive data hosted by third parties.
upvoted 1 times
...
Vima234
2 months, 1 week ago
Selected Answer: D
Since the CRM system contains personally identifiable information (PII), having clear and enforceable confidentiality terms is critical to ensuring the protection of sensitive data, the answer is option D
upvoted 2 times
...
Hayati
2 months, 3 weeks ago
the right wnswer is D
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...