リスク評価中に、主要な外部技術サプライヤーが機密保持上の懸念を理由に、制御設計と有効性に関する情報の提供を拒否しました。リスク管理担当者は次に何をすべきでしょうか?
正解:C
The next step for the risk practitioner when a key external technology supplier refuses to provide control design and effectiveness information is to review the supplier's contractual obligations. The contract between the organization and the supplier should specify the terms and conditions for the provision of the service or function, including the requirements for control design and effectiveness information. By reviewing the contract, the risk practitioner can determine if the supplier is breaching the contract and take appropriate actions to enforce the contract or terminate the relationship. Escalating the non-cooperation to management, excluding applicable controls from the assessment, and requesting risk acceptance from the business process owner are other possible steps, but they are not as effective as reviewing the supplier's contractual obligations. References = ISACA Certified in Risk and Information Systems Control (CRISC) Certification Exam Question and Answers, question 11; CRISC Review Manual, 6th Edition, page 144.