ある組織は、データ集約型のビジネス プロセスの一部にクラウドベースのサービス プロバイダーを採用することを計画しています。このアウトソーシング活動に関連する IT リスクを定義するために最も重要なのは次のどれですか。
正解:C
According to the CRISC Review Manual (Digital Version), the right to audit the provider is the most important factor to help define the IT risk associated with outsourcing activity to a cloud-based service provider, as it enables the organization to verify the compliance and performance of the provider with the contractual obligations and service level agreements. The right to audit the provider helps to:
Assess the security, availability, confidentiality, integrity, and privacy of the data and processes hosted by the provider Identify and evaluate the risks and controls related to the cloud-based services and the provider's infrastructure Monitor and measure the quality and effectiveness of the cloud-based services and the provider's governance and management practices Report and resolve any issues or incidents related to the cloud-based services and the provider's operations Ensure the alignment of the cloud-based services and the provider's policies and standards with the organization's objectives and requirements References = CRISC Review Manual (Digital Version), Chapter 3: IT Risk Response, Section 3.3: Risk Response Options, pp. 176-1771