nerdexam
CompTIA

CAS-001 · Question #83

A financial institution has decided to purchase a very expensive resource management system and has selected the product and vendor. The vendor is experiencing some minor, but public, legal issues…

The correct answer is A. Include a source code escrow clause in the contract for this system. A source code escrow arrangement requires the vendor to deposit the application's source code with a neutral third party. If the vendor ceases operations, goes bankrupt, or otherwise can no longer support the product, the escrow agent releases the source code to the purchaser…

Integration of Computing, Communications and Business Disciplines

Question

A financial institution has decided to purchase a very expensive resource management system and has selected the product and vendor. The vendor is experiencing some minor, but public, legal issues. Senior management has some concerns on maintaining this system should the vendor go out of business. Which of the following should the Chief Information Security Officer (CISO) recommend to BEST limit exposure?

Options

  • AInclude a source code escrow clause in the contract for this system.
  • BRequire proof-of-insurance by the vendor in the RFP for this system.
  • CInclude a penalty clause in the contract for this system.
  • DRequire on-going maintenance as part of the SLA for this system.

How the community answered

(36 responses)
  • A
    64% (23)
  • B
    11% (4)
  • C
    6% (2)
  • D
    19% (7)

Explanation

A source code escrow arrangement requires the vendor to deposit the application's source code with a neutral third party. If the vendor ceases operations, goes bankrupt, or otherwise can no longer support the product, the escrow agent releases the source code to the purchaser, allowing them to maintain or modify the system independently. This directly addresses the continuity risk. Proof-of-insurance and penalty clauses provide financial recourse but do not help the institution keep the system running. An SLA for ongoing maintenance is only enforceable while the vendor still exists-neither clause protects the institution if the vendor disappears.

Topics

#vendor risk management#source code escrow#contract management#third-party risk

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice