正解:D
According to the CRISC Review Manual1, a third-party audit is an independent and objective examination of an organization's security controls by an external auditor or organization. A third-party audit provides the most objective assessment of the effectiveness of an organization's security controls, as it helps to avoid any conflicts of interest, biases, or assumptions that may affect the internal audit, review, or testing. A third-party audit also helps to ensure that the security controls comply with the relevant standards, regulations, and best practices, and that they meet the expectations and requirements of the stakeholders, such as customers, partners, or regulators. References = CRISC Review Manual1, page 224.