正解:C
The risk practitioner's next course of action should be to review the contract and SLAs with the third-party cloud provider, as they define the roles, responsibilities, expectations, and obligations of both parties regarding the backup and recovery procedures. The contract and SLAs should specify the scope, frequency, quality, security, availability, and performance of the backup and recovery services, as well as the reporting, monitoring, auditing, and remediation mechanisms. The risk practitioner should ensure that the contract and SLAs are aligned with the organization's business continuity and disaster recovery requirements, and that they provide sufficient assurance and accountability for the third-party provider.
References:
*ISACA, Risk and Information Systems Control Review Manual, 7th Edition, 2020, p. 2501
*ISACA, Cloud Computing: Business Benefits With Security, Governance and Assurance Perspectives, 2009, p. 142
*ISACA, Guidelines on outsourcing to cloud service providers, 2020, p. 63