情報システム監査人が、インターネット経由で顧客が直接アクセスする Web ベースの顧客関係管理 (CRM) システムのセキュリティをレビューしています。次のうち、監査人が懸念すべきことはどれですか?
正解:A
An IS auditor should be concerned when an internet-facing system is hosted on an external third-party service provider's servers, as this could potentially increase the risk of data breaches or unauthorized access. External service providers may not have the same level of security controls and procedures as an internal corporate network, and the auditor should verify that the service provider has adequate measures in place to protect the customer data. The CISA Study Manual recommends that organizations and auditors should assess the security of cloud service providers and ensure that the service provider has appropriate security controls in place.