サードパーティの IT サービス プロバイダーが組織の人事 (HR) システムを海外でホストしていることがわかった場合、情報システム監査人の最善の推奨事項は何でしょうか。
正解:D
The best recommendation for an IS auditor when finding that a third-party IT service provider hosts the organization's HR system in a foreign country is to conduct a privacy impact analysis. A privacy impact analysis is a systematic process that identifies and evaluates the potential risks and impacts of collecting, using, disclosing, and storing personal information. A privacy impact analysis will help the IS auditor to assess the legal, regulatory, contractual, and ethical obligations of the organization and the service provider regarding the protection of personal information. A privacy impact analysis will also help to identify and mitigate any privacy risks and gaps in the service level agreement. References:
* CISA Certification | Certified Information Systems Auditor | ISACA
* CISA Questions, Answers & Explanations Database