nerdexam
CompTIA

CAS-001 · Question #132

Within the company, there is executive management pressure to start advertising to a new target market. Due to the perceived schedule and budget inefficiencies of engaging a technology business unit…

The correct answer is A. The third party should be contractually obliged to perform adequate security activities, and evidence. The best balance between business agility and risk management is to contractually obligate the third party to perform adequate security activities and provide evidence of compliance. This approach allows the marketing department to outsource and meet time-to-market demands…

Integration of Computing, Communications and Business Disciplines

Question

Within the company, there is executive management pressure to start advertising to a new target market. Due to the perceived schedule and budget inefficiencies of engaging a technology business unit to commission a new micro-site, the marketing department is engaging third parties to develop the site in order to meet time-to-market demands. From a security perspective, which of the following options BEST balances the needs between marketing and risk management?

Options

  • AThe third party should be contractually obliged to perform adequate security activities, and evidence
  • BOutsourcing is a valid option to increase time-to-market. If a security incident occurs, it is not of great
  • CThe company should never outsource any part of the business that could cause a security or privacy
  • DIf the third party has an acceptable record to date on security compliance and is provably faster and

How the community answered

(54 responses)
  • A
    54% (29)
  • B
    7% (4)
  • C
    13% (7)
  • D
    26% (14)

Explanation

The best balance between business agility and risk management is to contractually obligate the third party to perform adequate security activities and provide evidence of compliance. This approach allows the marketing department to outsource and meet time-to-market demands while ensuring the company retains accountability and oversight through enforceable contractual clauses - the standard mechanism for managing third-party risk. Option B is incorrect because a security incident from outsourcing is still the company's liability (e.g., data breach, regulatory fines). Option C is too extreme; outsourcing is a valid business practice when properly governed. Option D is insufficient because past performance does not guarantee current security posture without contractual obligations.

Topics

#vendor management#outsourcing#third-party risk#contractual security

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice