An IS auditor is evaluating controls for monitoring the regulatory compliance of a third party that provides IT services to the organization. Which of the following should be the auditor's GREATEST concern?
- A gap analysis against regulatory requirements has not been conducted.
- The third-party disclosed a policy-related issue of noncompliance.
- The organization has not reviewed the third party's policies and procedures.
- The organization has not communicated regulatory requirements to the third party.
Reveal Solution Next Question