nerdexam
CompTIA

CAS-001 · Question #170

(CRM) and marketing / leads management to Company XYZ. Which of the following is the MOST important to be considered before going ahead with the service?

The correct answer is C. Ensure there are security controls within the contract and the right to audit. When outsourcing sensitive data handling to a third party, the most critical requirement is ensuring the contract mandates security controls and grants the right to audit compliance.

Integration of Computing, Communications and Business Disciplines

Question

(CRM) and marketing / leads management to Company XYZ. Which of the following is the MOST important to be considered before going ahead with the service?

Options

  • AInternal auditors have approved the outsourcing arrangement.
  • BPenetration testing can be performed on the externally facing web system.
  • CEnsure there are security controls within the contract and the right to audit.
  • DA physical site audit is performed on Company XYZ's management / operation.

How the community answered

(20 responses)
  • B
    5% (1)
  • C
    90% (18)
  • D
    5% (1)

Why each option

When outsourcing sensitive data handling to a third party, the most critical requirement is ensuring the contract mandates security controls and grants the right to audit compliance.

AInternal auditors have approved the outsourcing arrangement.

Internal auditor approval is a governance step that may be required procedurally, but it does not by itself ensure the third party maintains adequate security controls over sensitive data.

BPenetration testing can be performed on the externally facing web system.

The ability to perform penetration testing on the external web system is a useful security assurance activity but is secondary to having contractual security obligations and audit rights in place.

CEnsure there are security controls within the contract and the right to audit.Correct

Embedding security controls and audit rights directly into the contract is the most important step because it creates legally enforceable obligations on the vendor, ensures accountability for data protection, and gives the organization the ability to verify compliance - without this, there is no mechanism to enforce security standards on the third party.

DA physical site audit is performed on Company XYZ's management / operation.

A physical site audit provides a point-in-time assessment of the vendor's operations but is less comprehensive and less continuously enforceable than contractual security controls with ongoing audit rights.

Concept tested: Third-party vendor risk management and contractual security controls

Source: https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/final

Topics

#outsourcing#third-party risk#contract security#right to audit

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice