ISC2 Governance, Risk and Compliance (CGRC) Practice Question
A critical cloud service provider renegotiates its SLA, shortening the maximum incident notification time from 48 to 24 hours. To stay compliant, what is the most appropriate action for the authorizing official's team?
Log the change in the contract repository but defer any monitoring adjustments until the next scheduled audit.
Revise the continuous monitoring strategy to include a control metric that verifies provider incident notifications occur within 24 hours and ensure collection mechanisms capture the data.
Require the provider to self-certify its compliance annually and discontinue in-house monitoring of incident notifications.
Escalate the SLA change to the Change Control Board and suspend all integrations with the provider until a full system re-authorization is completed.
Because the supplier's contractual obligation changed, the organization's continuous monitoring plan must be updated so the new 24-hour requirement is actually measured. Adding or revising a metric in the monitoring strategy and confirming data collection supports it ensures the organization can demonstrate the provider's compliance. Simply recording the contract change but waiting for the next audit, delegating monitoring to the supplier, or halting operations until a full re-authorization are either insufficient or unnecessarily disruptive and do not satisfy ongoing compliance responsibilities.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is continuous monitoring important in cloud service agreements?
Open an interactive chat with Bash
What is an SLA, and why are incident notifications included?
Open an interactive chat with Bash
What is the role of the authorizing official in compliance actions?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Compliance Maintenance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .