An organization shares some of its customers' personally identifiable information (PII) with third-party suppliers for business purposes. What is MOST important for the IS auditor to evaluate to ensure that risk associated with leakage of privacy-related data during transmission is effectively managed?
- Encrypting and masking of customer data
- The third party's privacy and data security policies
- Nondisclosure and indemnity agreements
- Service and operational level agreements
Reveal Solution Next Question