An IS auditor is evaluating controls for monitoring the regulatory compliance of a third party that provides IT services to the organization. Which of the following should be the auditor's GREATEST concern?
A.
A gap analysis against regulatory requirements has not been conducted.
B.
The third-party disclosed a policy-related issue of noncompliance.
C.
The organization has not reviewed the third party's policies and procedures.
D.
The organization has not communicated regulatory requirements to the third party.
I think answer is C. If we reviewed other parties policies and procedures and do due diligence activities then even we couldnt submit our requirements it may be low or medium risk, because maybe we already check if third party is compliant. But if policies/procedures are not checked or due diligence performed that means we don't have any third party risk management that makes it high risk finding. Even we submit our requirements maybe other is not followed them.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Pumeza
1 week, 1 day ago[Removed]
4 months ago[Removed]
4 months agoa84n
6 months, 3 weeks ago5b56aae
7 months agosundersam23
9 months, 2 weeks agoPC2323
1 year, 2 months agoAB1237
1 year, 2 months agosbtt
1 year, 3 months agoVarokah
7 months, 1 week agokclow
1 year, 2 months agofrisbg
1 year, 5 months agocidigi
1 year, 3 months agoKandyd
1 year, 10 months ago