CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium
A global e-commerce company uses a third-party payment gateway to process all customer transactions. As part of its risk management framework, the company regularly reviews the payment gateway's security certifications, audit reports, and incident response plans. Which of the following control monitoring activities is the company primarily performing?
- APenetration Testing
- BInternal Control Self-Assessment
- CThird-Party Assurance Review
- DContinuous Auditing
Show answer & explanationAnswer & explanation
Correct answer: C. Third-Party Assurance Review
Reviewing security certifications, audit reports, and incident response plans of a third-party vendor is a classic example of third-party assurance review. This activity ensures that the external service provider meets the organization's security and control requirements.
Why the other options are wrong
- A. Penetration testing is an active security test to find vulnerabilities, not a review of documentation.
- B. Internal control self-assessment is performed by the organization on its own controls.
- D. Continuous auditing involves automated, real-time monitoring of internal systems.
Third-Party Assurance Review
The process of evaluating the effectiveness of controls implemented by an external service provider.
- Crucial for managing supply chain risk.
- Often involves reviewing SOC reports, certifications, and security policies.
- Ensures third parties align with organizational risk appetite and requirements.
Memory trick: Monitoring external parties needs assurance.