ビジネス プロセス用の Software as a Service (SaaS) ベンダーを選択する際に、ベンダーは世界的に認められた情報セキュリティ認証の証拠を提供します。次のうち、最も重要な考慮事項はどれですか。
正解:C
The most important consideration when selecting a SaaS vendor for a business process is whether the vendor' s information security certification is issued for the specific scope of the service that the organization needs. A certification that covers the entire vendor organization or a different service may not be relevant or sufficient for the organization's security requirements. The certification should also include industry-recognized security controls, be issued within a reasonable time frame, and be easily verified, but these are not as critical as the scope. References = CISM Review Manual, 16th Edition, page 1841; 5 Top SaaS Security Certifications for SaaS Providers