Certified in Risk and Information Systems Control (CRISC) — Question 679
Which of the following is the MOST common concern associated with outsourcing to a service provider?
Answer options
- A. Combining incompatible duties
- B. Unauthorized data usage
- C. Denial of service (DoS) attacks
- D. Lack of technical expertise
Correct answer: B
Explanation
The correct answer is B, as unauthorized data usage poses significant risks regarding data privacy and compliance when outsourcing. While combining incompatible duties, denial of service attacks, and lack of technical expertise are valid concerns, they do not directly address the critical issue of data security that often arises with outsourcing arrangements.