次のどれが、サードパーティのサービスプロバイダーの情報セキュリティ管理が有効であることを IS 監査人に最もよく示す証拠になりますか?
正解:C
Comprehensive and Detailed Step-by-Step Explanation: Toverify the effectivenessof a third-party provider'ssecurity controls, anindependent external audit reportis thestrongestevidence. * Option A (Incorrect):Security configuration documentsare helpful butdo not confirm effectivenesswithout validation. * Option B (Incorrect):Policies and procedures outlineintent, but anaudit confirms actual implementation. * Option C (Correct):External audit reports (e.g., SOC 2, ISO 27001)provideindependent assurancethat security controls are effective. * Option D (Incorrect):Management interviews providequalitativeinsights but arenot objective evidenceof control effectiveness. Reference:ISACA CISA Review Manual -Domain 3: Information Systems Acquisition, Development, and Implementation- Coversthird-party risk assessments and audit assurance.