nerdexam
CompTIA

CAS-001 · Question #272

A wholesaler has decided to increase revenue streams by selling direct to the public through an on- line system. Initially this will be run as a short term trial and if profitable, will be expanded…

The correct answer is C. Transfer the initial risks by outsourcing payment processing to a third party service provider. Outsourcing payment processing to a qualified third party transfers both the PCI DSS compliance burden and the skills gap risk to a vendor already certified to handle them.

Integration of Computing, Communications and Business Disciplines

Question

A wholesaler has decided to increase revenue streams by selling direct to the public through an on- line system. Initially this will be run as a short term trial and if profitable, will be expanded and form part of the day to day business. The risk manager has raised two main business risks for the initial trial: 1. IT staff has no experience with establishing and managing secure on- line credit card processing. 2. An internal credit card processing system will expose the business to additional compliance requirements. Which of the following is the BEST risk mitigation strategy?

Options

  • ATransfer the risks to another internal department, who have more resources to accept the risk.
  • BAccept the risks and log acceptance in the risk register. Once the risks have been accepted close
  • CTransfer the initial risks by outsourcing payment processing to a third party service provider.
  • DMitigate the risks by hiring additional IT staff with the appropriate experience and certifications.

How the community answered

(25 responses)
  • A
    8% (2)
  • B
    20% (5)
  • C
    68% (17)
  • D
    4% (1)

Why each option

Outsourcing payment processing to a qualified third party transfers both the PCI DSS compliance burden and the skills gap risk to a vendor already certified to handle them.

ATransfer the risks to another internal department, who have more resources to accept the risk.

Transferring the risk to another internal department does not eliminate either risk since the organization as a whole still bears the compliance and expertise burden.

BAccept the risks and log acceptance in the risk register. Once the risks have been accepted close

Accepting and logging the risks as closed is inappropriate when viable mitigation options exist and the risks carry significant compliance and financial consequences.

CTransfer the initial risks by outsourcing payment processing to a third party service provider.Correct

Engaging a third-party payment processor transfers both identified risks - staff inexperience with secure card processing and the PCI DSS compliance exposure - to a provider that is already audited and certified for those requirements. This is the most effective short-term strategy because it removes the organization from the scope of certain PCI DSS controls while the trial runs. For a limited-duration trial, outsourcing avoids the cost and delay of building internal capability before validating the business model.

DMitigate the risks by hiring additional IT staff with the appropriate experience and certifications.

Hiring additional staff with certifications takes considerable time, does not immediately satisfy PCI DSS audit requirements, and overinvests resources in a short-term trial of unproven profitability.

Concept tested: Risk transfer through third-party outsourcing

Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

Topics

#risk transfer#PCI DSS#outsourcing#risk management

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice