712-50 · Question #228
The ability to demand the implementation and management of security controls on third parties providing services to an organization is
The correct answer is C. Vendor management. Vendor management focuses on the oversight of third-party providers. This includes ensuring they meet security standards, contractual obligations, and comply with relevant regulations. Requiring implementation and management of security controls is a key part of this process…
Question
The ability to demand the implementation and management of security controls on third parties providing services to an organization is
Options
- ASecurity Governance
- BCompliance management
- CVendor management
- DDisaster recovery
How the community answered
(56 responses)- A9% (5)
- B4% (2)
- C70% (39)
- D18% (10)
Explanation
Vendor management focuses on the oversight of third-party providers. This includes ensuring they meet security standards, contractual obligations, and comply with relevant regulations. Requiring implementation and management of security controls is a key part of this process. Disaster recovery is about restoring services after an outage. While security is important in disaster recovery, it's not the primary focus of requiring security controls in third-party services. Security governance is a broader framework of policies and processes for managing organizational security. While vendor management falls under it, it's not the specific aspect highlighted in the question. Compliance management ensures adherence to laws and regulations. It's related to vendor management, but the question focuses specifically on the ability to require security controls, which is a vendor management function.
Topics
Community Discussion
No community discussion yet for this question.