Q: 16
An information security team is planning a security assessment of an existing vendor. Which of the
following approaches is MOST helpful for properly scoping the assessment?
Options
Discussion
Why not D? Reviewing the vendor's security policy might help you get a sense of their actual controls.
Its B
B, This matches what I've seen in similar practice questions, since the contract really lays out the security controls you actually expect from the vendor. Super clear wording here.
Be respectful. No spam.
Question 16 of 35