An information security manager has been asked to provide contract guidance from a security perspective for outsourcing the organization's payroll processing Which of the following is MOST important to address?
A.
Vendor compliance with the most stringent data security regulations
B.
Vendor compliance with the organization's information security policies
C.
Vendor compliance with organizational service level agreement (SLA) requirements
D.
Vendor compliance with recognized industry security standards
The Correct answer is (B) Vendor compliance with the organization's information security policies. Without the vendor adhering to the organization's security policies the org's critical information is surely going to be at risk.
Rationale
(A) Just because the vendor is complying with the most stringent data security regulations doesn't mean that it is meeting the org's security policy as the org could have some obtuse or org-specific policy that isn't covered by the regulation.
(C.)SLA don't may or may not be security related. (B) is a better answer in this case.
(D) Vendor compliance with recognized industry security standards doesn't mean that it will be compliant with the ORG's security policy and posture.
So as you can see the only one that truly aligns with the org's security stance is (B) Vendor compliance with the organization's information security policies.
best answer would be compliance to PDPA or similar regulations, but if hypothetically the org have implemented controls/practices based on industry standard, B would be a great answer
The vendor complies with the organization's information security policies (option B) is important, those policies may vary from one organization to another and may not cover all security aspects that industry standards encompass. Therefore, industry security standards are often considered a more critical benchmark when outsourcing critical functions like payroll processing.
Question says 'from a security perspective' therefore answer is B. The Security Manager will not be concerned about the legal or performance stuff contained in the SLA
Would be B as from a security perspective this would ensure they manage and treat the payroll data to the same standard.
From a security perspective the service level of payroll management is not crucial (so long as the data is secure/meets policy it doesn't matter when people get paid etc)
upvoted 2 times
...
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
dark_3k03r
Highly Voted 1 year, 7 months agovickyguna78
Most Recent 3 months, 3 weeks agojcisco123
11 months agoKing21
12 months ago[Removed]
1 year agorichck102
1 year, 5 months agoCarlPTY07
1 year, 8 months agobambs
1 year, 10 months agoRowlandmarc
1 year, 8 months ago