To ensure the information security of outsourced IT services, which of the following is the MOST critical due diligence activity?
A. Review samples of service level reports from the service
provider.
B. Assess the level of security awareness of the service
provider.
C. Request that the service provider comply with information
security policy.
D. Review the security status of the service provider.
Correct Answer: C?? or D???
Solution:
The answer is option D.
Explanation:
In order to ensure the information security of the outsourced IT services, the service provider must comply with the security policies that are stated by the company.
The above activity stated must takes place after conducting the business.
Due diligence activity is the activity which includes the examination of the financial records and other standards of the party before proceeding to start their business.
So, during the due diligence activity, the security status of the service provider must be reviewed.
If the security status is found satisfactory during the due diligence activity, then the business or the proposed transaction can be proceeded further.
When the business starts between the parties, then the service provider must also comply with the security policies that are defined in the business.
Get Answers For Free
Most questions answered within 1 hours.