🔥 3-day streak
ISACA CRISC — Certified in Risk and Information Systems Control15 / 150
Question 15 of 150

A financial services firm outsources its customer data processing to a third-party cloud provider. The contract includes a service-level agreement (SLA) requiring 99.9% availability and specific data-breach notification timelines mandated by the firm's regulator. During a governance review, the risk manager notes that no internal party has been formally assigned to monitor the provider's adherence to these contractual and regulatory obligations. Which action should the risk manager recommend FIRST?

Reviewed for accuracy · Report an issueNext question