nerdexam
CompTIA

CAS-001 · Question #51

A bank has just outsourced the security department to a consulting firm, but retained the security architecture group. A few months into the contract the bank discovers that the consulting firm has…

The correct answer is B. Ensure the consulting firm has service agreements with the sub-contractor; if the agreement does. In vendor/third-party risk management, the primary contract holder (the consulting firm) remains responsible for service delivery and compliance. The bank's legal and service protections flow through the prime contract with the consulting firm - not through a direct…

Integration of Computing, Communications and Business Disciplines

Question

A bank has just outsourced the security department to a consulting firm, but retained the security architecture group. A few months into the contract the bank discovers that the consulting firm has sub-contracted some of the security functions to another provider. Management is pressuring the sourcing manager to ensure adequate protections are in place to insulate the bank from legal and service exposures. Which of the following is the MOST appropriate action to take?

Options

  • ADirectly establish another separate service contract with the sub-contractor to limit the risk exposure
  • BEnsure the consulting firm has service agreements with the sub-contractor; if the agreement does
  • CLog it as a risk in the business risk register and pass the risk to the consulting firm for acceptance
  • DTerminate the contract immediately and bring the security department in-house again to reduce

How the community answered

(49 responses)
  • A
    8% (4)
  • B
    45% (22)
  • C
    31% (15)
  • D
    16% (8)

Explanation

In vendor/third-party risk management, the primary contract holder (the consulting firm) remains responsible for service delivery and compliance. The bank's legal and service protections flow through the prime contract with the consulting firm - not through a direct relationship with sub-contractors. The correct action is to ensure the consulting firm has appropriate service agreements with the sub-contractor that mirror or align with the bank's requirements (e.g., security standards, SLAs, audit rights, data handling). If those agreements are not in place or are deficient, the bank should require remediation through the prime contractor. Option A creates a tangled, dual-contract liability and undermines the prime contractor's accountability. Option C merely documents the risk without resolving it. Option D is a drastic, costly reaction when a contractual resolution is available.

Topics

#vendor management#outsourcing risk#service agreements#third-party governance

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice