A company engages a third-party vendor to process customer data. Which of the following is the most critical step in managing the associated risk?
Pre-contract due diligence is the most critical to identify and mitigate risks early.
Why this answer
Conducting due diligence before contracting is essential to identify risks and ensure the vendor meets security requirements. Vulnerability scans are part of due diligence but not the most critical step. NDA and liability clauses are important but secondary to initial assessment.