The Chief Information Officer (CIO) asked a vendor to provide documentation detailing the specific objectives within the compliance framework that the vendor's services meet. The vendor provided a report and a signed letter stating that the services meet 17 of the 21 objectives. Which of the following did the vendor provide to the CIO?
Choose an answer
Tap an option to check your answer.
Correct answer: Attestation of compliance.
Why this is the answer
An attestation of compliance is a formal statement, often a signed letter, from a vendor or third party confirming that their services or systems meet specific compliance objectives or standards. In this scenario, the vendor provided a report and a signed letter detailing which objectives their services meet, directly aligning with the definition of an attestation. Penetration test results would detail vulnerabilities found during a simulated attack, not compliance objectives. Self-assessment findings are internal evaluations, not typically provided as a formal, signed statement to a client regarding compliance. A third-party audit report would involve an independent auditor's detailed examination and opinion, which is more extensive and formal than what was described.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed