🔥 3-day streak
ISACA CRISC — Certified in Risk and Information Systems Control143 / 150
Question 143 of 150
A retailer relies on a cloud-based payment processor and receives an annual SOC 2 Type II report from the vendor as its primary source of assurance over the vendor's controls. During the year, the vendor migrates its infrastructure to a new data center and adds a new subprocessor. Which action should the risk practitioner recommend to best address the resulting third-party risk monitoring gap?
Reviewed for accuracy · Report an issueNext question