Outsourced payroll is omitted from entity scope because “it is not on our servers.” The city remains accountable for employee data protection. What correction is needed?
Select an answer to reveal the explanation.
Short Explanation
“Not our servers” is not the same as “not our problem.” If the city is still on the hook for employee data, the outsourced payroll service belongs in entity scope. Accountability follows the obligation, not the rack location.
Full Explanation
Entity scope should follow accountability and regulatory applicability, including third-party-hosted services the organization remains responsible for. Excluding outsourced payroll solely because infrastructure is external creates false gaps in privacy and control coverage. Represent the service (and related vendor relationship as appropriate) so assessments and controls can attach. Light vendor-entity awareness belongs here; deep TPRM product implementation is out of CIS-RC scope.