A global organization is reviewing potential vendors to outsource a critical payroll function. Each vendor's plan includes using local resources in multiple regions to ensure compliance with all regulations. The organization's Chief Information Security Officer is conducting a risk assessment on the potential outsourcing vendors' subprocessors. Which of the following best explains the need for this risk assessment?
Select an option, then click Submit answer.
- ○ Risk mitigations must be more comprehensive than the existing payroll provider.
- ○ Due care must be exercised during all procurement activities.
- ○ The responsibility of protecting PII remains with the organization.
- ○ Specific regulatory requirements must be met in each jurisdiction.