Question 1 of 30
\"DataSecure Ltd.\" is a company specializing in data analytics and provides services to various clients across different industries. They are implementing a new data processing system that handles personal data from multiple sources. As a lead auditor evaluating DataSecure\'s compliance with ISO 29100, you are reviewing their approach to third-party management. Which of the following options best reflects the key principles of third-party management that DataSecure should incorporate into their data processing system, according to ISO 29100?
Conduct thorough assessments of third-party privacy practices, establish contractual obligations for third-party vendors to ensure compliance with privacy requirements, and monitor third-party compliance regularly to manage risks effectively.
Primarily focus on selecting third-party vendors based on cost-effectiveness, while addressing privacy concerns on an ad-hoc basis as needed.
Delegate the responsibility of third-party management to the legal department, relying solely on their expertise to negotiate contracts with third-party vendors.
Conduct a one-time security audit of third-party vendors at the initial stage of engagement, and then rely on annual security audits to ensure ongoing compliance with privacy regulations.