nerdexam
CompTIA

CAS-001 · Question #228

The company is about to upgrade a financial system through a third party, but wants to legally ensure that no sensitive information is compromised throughout the project. The project manager must…

The correct answer is A. Separation of duties E. NDA. An NDA provides the legal protection against disclosure of sensitive information to the third party, and separation of duties limits the damage any single internal employee can cause during the upgrade.

Integration of Computing, Communications and Business Disciplines

Question

The company is about to upgrade a financial system through a third party, but wants to legally ensure that no sensitive information is compromised throughout the project. The project manager must also make sure that internal controls are set to mitigate the potential damage that one individual's actions may cause. Which of the following needs to be put in place to make certain both organizational requirements are met? (Select TWO).

Options

  • ASeparation of duties
  • BForensic tasks
  • CMOU
  • DOLA
  • ENDA
  • FJob rotation

How the community answered

(28 responses)
  • A
    79% (22)
  • B
    7% (2)
  • C
    11% (3)
  • D
    4% (1)

Why each option

An NDA provides the legal protection against disclosure of sensitive information to the third party, and separation of duties limits the damage any single internal employee can cause during the upgrade.

ASeparation of dutiesCorrect

Separation of duties divides critical tasks among multiple individuals so that no single person has the ability to perform, authorize, and conceal a damaging action, directly mitigating the risk of one individual causing significant harm during the financial system upgrade.

BForensic tasks

Forensic tasks are investigative procedures conducted after a security incident has occurred and do not prevent data compromise or limit individual access during a project.

CMOU

A Memorandum of Understanding (MOU) documents a general agreement between parties but is not legally binding and therefore does not legally ensure sensitive information is protected.

DOLA

An Operational Level Agreement (OLA) defines service levels between internal teams and does not address legal confidentiality with external third parties.

ENDACorrect

A Non-Disclosure Agreement (NDA) is a legally binding contract that obligates the third-party vendor and its personnel to keep all sensitive organizational information confidential, directly satisfying the legal requirement to prevent information compromise.

FJob rotation

Job rotation is a long-term internal control that reduces fraud risk over time but does not directly address the immediate legal requirement to protect information shared with a third party.

Concept tested: NDA for third-party data protection and separation of duties

Source: https://learn.microsoft.com/en-us/compliance/assurance/assurance-supplier-management

Topics

#NDA#separation of duties#third-party risk#internal controls

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice