CAS-002 · Question #129
Within the company, there is executive management pressure to start advertising to a new target market. Due to the perceived schedule and budget inefficiencies of engaging a technology business unit…
The correct answer is A. The third party should be contractually obliged to perform adequate security activities, and. When outsourcing to third parties, the best approach is to use contractual obligations to enforce security requirements while still achieving time-to-market goals.
Question
Within the company, there is executive management pressure to start advertising to a new target market. Due to the perceived schedule and budget inefficiencies of engaging a technology business unit to commission a new micro-site, the marketing department is engaging third parties to develop the site in order to meet time-to-market demands. From a security perspective, which of the following options BEST balances the needs between marketing and risk management?
Options
- AThe third party should be contractually obliged to perform adequate security activities, and
- BOutsourcing is a valid option to increase time-to-market. If a security incident occurs, it is
- CThe company should never outsource any part of the business that could cause a security
- DIf the third party has an acceptable record to date on security compliance and is provably
How the community answered
(17 responses)- A71% (12)
- B6% (1)
- C18% (3)
- D6% (1)
Why each option
When outsourcing to third parties, the best approach is to use contractual obligations to enforce security requirements while still achieving time-to-market goals.
Contractual security obligations are the industry-standard mechanism for managing third-party risk without blocking business objectives. This approach holds the vendor legally accountable for security activities while still enabling marketing to meet its time-to-market demands, effectively balancing business agility with risk management.
Accepting that a security incident is solely the third party's responsibility does not protect the company from reputational, legal, or financial damage resulting from a breach on its behalf.
A blanket prohibition on outsourcing is an overly restrictive policy that ignores legitimate business needs and the ability to contractually enforce security standards on third parties.
A vendor's past compliance record alone does not guarantee future security posture - contractual obligations and ongoing oversight are still required to manage risk appropriately.
Concept tested: Third-party risk management via contractual security obligations
Source: https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.