A system owner wants to share a risk assessment report with a third-party cloud provider. Which concern should be addressed first?
-
A
Whether the report contains sensitive vulnerability details that could aid attackers if disclosed
-
B
Whether the third party has a FISMA-compliant system of their own
-
C
Whether the report has been approved by the agency CIO for distribution
-
D
Whether the cloud provider is listed in the GSA Schedule