An organization uses a third-party vendor that will have access to sensitive customer data. Which compliance best practice is MOST critical before engagement?
-
A
Requiring the vendor to carry general liability insurance
-
B
Conducting due diligence and executing a data processing agreement
-
C
Verifying the vendor's physical office location
-
D
Ensuring the vendor uses the same software platforms