CAS-001 · Question #170
(CRM) and marketing / leads management to Company XYZ. Which of the following is the MOST important to be considered before going ahead with the service?
The correct answer is C. Ensure there are security controls within the contract and the right to audit. When outsourcing sensitive data handling to a third party, the most critical requirement is ensuring the contract mandates security controls and grants the right to audit compliance.
Question
(CRM) and marketing / leads management to Company XYZ. Which of the following is the MOST important to be considered before going ahead with the service?
Options
- AInternal auditors have approved the outsourcing arrangement.
- BPenetration testing can be performed on the externally facing web system.
- CEnsure there are security controls within the contract and the right to audit.
- DA physical site audit is performed on Company XYZ's management / operation.
How the community answered
(20 responses)- B5% (1)
- C90% (18)
- D5% (1)
Why each option
When outsourcing sensitive data handling to a third party, the most critical requirement is ensuring the contract mandates security controls and grants the right to audit compliance.
Internal auditor approval is a governance step that may be required procedurally, but it does not by itself ensure the third party maintains adequate security controls over sensitive data.
The ability to perform penetration testing on the external web system is a useful security assurance activity but is secondary to having contractual security obligations and audit rights in place.
Embedding security controls and audit rights directly into the contract is the most important step because it creates legally enforceable obligations on the vendor, ensures accountability for data protection, and gives the organization the ability to verify compliance - without this, there is no mechanism to enforce security standards on the third party.
A physical site audit provides a point-in-time assessment of the vendor's operations but is less comprehensive and less continuously enforceable than contractual security controls with ongoing audit rights.
Concept tested: Third-party vendor risk management and contractual security controls
Source: https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.