When evaluating vendors for sensitive data processing, which of the following should be the FIRST step to ensure the correct level of information security is provided?
A.
Develop metrics for vendor performance.
B.
Include information security criteria as part of vendor selection.
C.
Review third-party reports of potential vendors.
D.
Include information security clauses in the vendor contract.
I would also say B and then C. First you develop criteria that you include in vendor selection, then you go about reading third-party reports and compare what's in the report against the criteria.
Including information security criteria as part of the vendor selection process ensures that security considerations are integrated into the initial evaluation. This step involves assessing the security posture of potential vendors against predefined criteria before proceeding with further evaluation or contractual agreements. It helps filter out vendors that do not meet the required information security standards from the outset.
While the other options (developing metrics for vendor performance, reviewing third-party reports, and including information security clauses in the vendor contract) are important steps in the overall vendor management process, incorporating information security criteria early in the vendor selection process is critical for establishing a foundation of security in the relationship from the beginning.
Once an organization has established its third-party risk classification and has begun to identify its third parties and their respective risk tiering, third parties can be assessed.
Before assessments can be performed, however, the organization needs to develop a scheme. -AIO Book
choices A,B,D they are right steps. however they come after the easiest step which is C.
no organization in reality will develop performance metrics before checking available public recent third-party audit reports. the sequence is important. C is first and other remaining will be after.
The first step is getting available info in public like third-party reviews.
Before proceeding in other steps that may be still important.
but as order, the first step is getting third-party vendor report like gartner report for example.
right answer is C.
I would disagree, for ex. ensuring systems data is encrypted at rest and in transit is a critical security criteria and is not a metric, nor does it feed into metrics.
The correct answer is C. Reviewing third-party reports of potential vendors is the first step to ensure the correct level of information security is provided. These reports may include results of security audits or assessments, which can provide valuable information on a vendor's security controls and risks. This information can be used to evaluate the vendor's security posture and make an informed decision about whether to engage with them. The other options are also important steps in the process, but they come after reviewing the reports of potential vendors.
I would agree with B. I have seen many RFPs that included client data protection needs. You want to be upfront with your needs and exclude vendors that don't meet your needs prior to going into a contract.
D is necessary but not the FIRST step, B is first then D once the vendor was selected
upvoted 2 times
...
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
AlexJacobson
1 month, 3 weeks agoViperhunter
1 month, 3 weeks agogreeklover84
2 months agojust2pass
8 months, 3 weeks agoMrSecNetTech
1 year, 1 month agoMrSecNetTech
1 year, 1 month agoYemmz
1 year, 4 months agoAzurefox79
1 year, 3 months agorichck102
1 year, 6 months agoTsubasa1234
1 year, 7 months agod3vnu77
1 year, 9 months agoAntonivs
1 year, 10 months agoD2D2
1 year, 11 months agoEZPASS
2 years agoBoats
2 years, 1 month agoTay87543
2 years, 1 month agoaaaa234
2 years, 1 month agomfourati
1 year, 11 months ago