nerdexam
EC-Council

712-50 · Question #228

The ability to demand the implementation and management of security controls on third parties providing services to an organization is

The correct answer is C. Vendor management. Vendor management focuses on the oversight of third-party providers. This includes ensuring they meet security standards, contractual obligations, and comply with relevant regulations. Requiring implementation and management of security controls is a key part of this process…

Strategic Planning, Finance, Procurement, and Vendor Management

Question

The ability to demand the implementation and management of security controls on third parties providing services to an organization is

Options

  • ASecurity Governance
  • BCompliance management
  • CVendor management
  • DDisaster recovery

How the community answered

(56 responses)
  • A
    9% (5)
  • B
    4% (2)
  • C
    70% (39)
  • D
    18% (10)

Explanation

Vendor management focuses on the oversight of third-party providers. This includes ensuring they meet security standards, contractual obligations, and comply with relevant regulations. Requiring implementation and management of security controls is a key part of this process. Disaster recovery is about restoring services after an outage. While security is important in disaster recovery, it's not the primary focus of requiring security controls in third-party services. Security governance is a broader framework of policies and processes for managing organizational security. While vendor management falls under it, it's not the specific aspect highlighted in the question. Compliance management ensures adherence to laws and regulations. It's related to vendor management, but the question focuses specifically on the ability to require security controls, which is a vendor management function.

Topics

#vendor management#third-party security#security controls#outsourcing

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice