CompTIA SecurityX (CAS-005) CAS-005 — Question 396
Topic 1 · Question 396 of 393
Topic 1 · Question 396
A Chief Information Security Officer (CISO) is developing a third-party risk management program and wants to establish an order of preference for solicitation and acceptance of audit and assessment results from business partners. The CISO prefers a formal certification against an established framework, which should be considered more reliable than self-attestations. Which of the following is most likely the reason for this perspective?