CAS-001 · Question #228
The company is about to upgrade a financial system through a third party, but wants to legally ensure that no sensitive information is compromised throughout the project. The project manager must…
The correct answer is A. Separation of duties E. NDA. An NDA provides the legal protection against disclosure of sensitive information to the third party, and separation of duties limits the damage any single internal employee can cause during the upgrade.
Question
The company is about to upgrade a financial system through a third party, but wants to legally ensure that no sensitive information is compromised throughout the project. The project manager must also make sure that internal controls are set to mitigate the potential damage that one individual's actions may cause. Which of the following needs to be put in place to make certain both organizational requirements are met? (Select TWO).
Options
- ASeparation of duties
- BForensic tasks
- CMOU
- DOLA
- ENDA
- FJob rotation
How the community answered
(28 responses)- A79% (22)
- B7% (2)
- C11% (3)
- D4% (1)
Why each option
An NDA provides the legal protection against disclosure of sensitive information to the third party, and separation of duties limits the damage any single internal employee can cause during the upgrade.
Separation of duties divides critical tasks among multiple individuals so that no single person has the ability to perform, authorize, and conceal a damaging action, directly mitigating the risk of one individual causing significant harm during the financial system upgrade.
Forensic tasks are investigative procedures conducted after a security incident has occurred and do not prevent data compromise or limit individual access during a project.
A Memorandum of Understanding (MOU) documents a general agreement between parties but is not legally binding and therefore does not legally ensure sensitive information is protected.
An Operational Level Agreement (OLA) defines service levels between internal teams and does not address legal confidentiality with external third parties.
A Non-Disclosure Agreement (NDA) is a legally binding contract that obligates the third-party vendor and its personnel to keep all sensitive organizational information confidential, directly satisfying the legal requirement to prevent information compromise.
Job rotation is a long-term internal control that reduces fraud risk over time but does not directly address the immediate legal requirement to protect information shared with a third party.
Concept tested: NDA for third-party data protection and separation of duties
Source: https://learn.microsoft.com/en-us/compliance/assurance/assurance-supplier-management
Topics
Community Discussion
No community discussion yet for this question.