Q: 20
To confirm that a third-party provider complies with an organization's information security
requirements, it is MOST important to ensure:
Options
Discussion
Nah, B looks tempting but without D you can't actually verify anything. D gives you the teeth to check compliance. D.
Having the right to audit in the SLA is huge for real verification, not just paperwork or promises. D lets you actually check how things are running. Pretty sure that's what CISM wants here.
D based on official guide and practice questions I've seen. Right to audit is always flagged as critical for third-party compliance.
B or D? B seems solid since contract clauses can enforce what’s required by policy, which should push compliance, but I get why audit rights (D) are a big deal too. Think some exams trip you up with B as a close trap.
Probably D. Without audit rights, you can't really confirm actual compliance even if all the paperwork looks good.
Be respectful. No spam.
Question 20 of 35