What would be an information security manager's BEST recommendation upon learning that an existing contract with a third party does not clearly identify requirements for safeguarding the organization's critical data?
A.
Cancel the outsourcing contract.
B.
Transfer the risk to the provider.
C.
Create an addendum to the existing contract.
D.
Initiate an external audit of the provider's data center.
The Definition of an addendum is an item of additional material added at the end of a book or document, typically in order to correct, clarify, or supplement something.
Seeing that this needs to be addressed, Option C is the only correct answer.
Creating an addendum allows the organization to update and clarify the contract terms related to the safeguarding of critical data without necessarily canceling the contract or transferring all the risk to the provider. This approach enables a more targeted and specific resolution to address the security concerns while maintaining the existing business relationship.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
dark_3k03r
1 month, 3 weeks agoViperhunter
12 months agopeelu
1 year, 5 months agorichck102
1 year, 6 months agojaiz
1 year, 8 months agoStarfive
1 year, 9 months agoPrasannacpw
1 year, 11 months ago