IAPP CIPP/US Practice Exam

Category - Professional

Effective vendor management policies typically involves (1)  due diligence in ensuring a third-party vendor with whom the organization’s sensitive data is shared is implementing reasonable and appropriate security measures; (2) obligations by the organization to the third party vendor to implement reasonable and necessary safeguards and (3) ______________________________.
  1. Shared cybersecurity service provider by the organization and vendor
  2. Acknowledgement of accountability by the vendor or data processor
  3. Routine monitoring of the third-party vendor to ensure compliance with contractual provisions
  4. Direct contract between the data subject and the third-party vendor
Explanation
Answer: C - Effective vendor management policies typically involve routine monitoring of the third-party vendor by the organization to ensure compliance with contractual provisions. This monitoring supports the organization’s due diligence in ensuring the vendor’s implementation of reasonable and appropriate security measures. In addition, contracts typically set out the vendor’s responsibility to uphold the privacy and security of data provided by the organization (the data controller).
 
The data controller is responsible for protecting the data it collects, uses, and shares. Data processing vendors should be held accountable for protecting the sensitive information shared with them.
Was this helpful? Upvote!
Login to contribute your own answer or details

Top questions

Related questions

Most popular on PracticeQuiz