CISM Certified Information Security Manager – Question0719

Which of the following is the BEST way to address any gaps identified during an outsourced provider selection and contract negotiation process?

A.
Make the provider accountable for security and compliance
B. Perform continuous gap assessments
C. Include audit rights in the service level agreement (SLA)
D. Implement compensating controls

Correct Answer: C