nerdexam
CompTIA

CAS-002 · Question #129

Within the company, there is executive management pressure to start advertising to a new target market. Due to the perceived schedule and budget inefficiencies of engaging a technology business unit…

The correct answer is A. The third party should be contractually obliged to perform adequate security activities, and. When outsourcing to third parties, the best approach is to use contractual obligations to enforce security requirements while still achieving time-to-market goals.

Integration of Computing, Communications and Business Disciplines

Question

Within the company, there is executive management pressure to start advertising to a new target market. Due to the perceived schedule and budget inefficiencies of engaging a technology business unit to commission a new micro-site, the marketing department is engaging third parties to develop the site in order to meet time-to-market demands. From a security perspective, which of the following options BEST balances the needs between marketing and risk management?

Options

  • AThe third party should be contractually obliged to perform adequate security activities, and
  • BOutsourcing is a valid option to increase time-to-market. If a security incident occurs, it is
  • CThe company should never outsource any part of the business that could cause a security
  • DIf the third party has an acceptable record to date on security compliance and is provably

How the community answered

(17 responses)
  • A
    71% (12)
  • B
    6% (1)
  • C
    18% (3)
  • D
    6% (1)

Why each option

When outsourcing to third parties, the best approach is to use contractual obligations to enforce security requirements while still achieving time-to-market goals.

AThe third party should be contractually obliged to perform adequate security activities, andCorrect

Contractual security obligations are the industry-standard mechanism for managing third-party risk without blocking business objectives. This approach holds the vendor legally accountable for security activities while still enabling marketing to meet its time-to-market demands, effectively balancing business agility with risk management.

BOutsourcing is a valid option to increase time-to-market. If a security incident occurs, it is

Accepting that a security incident is solely the third party's responsibility does not protect the company from reputational, legal, or financial damage resulting from a breach on its behalf.

CThe company should never outsource any part of the business that could cause a security

A blanket prohibition on outsourcing is an overly restrictive policy that ignores legitimate business needs and the ability to contractually enforce security standards on third parties.

DIf the third party has an acceptable record to date on security compliance and is provably

A vendor's past compliance record alone does not guarantee future security posture - contractual obligations and ongoing oversight are still required to manage risk appropriately.

Concept tested: Third-party risk management via contractual security obligations

Source: https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/final

Topics

#third-party risk#outsourcing security#contractual obligations#risk management

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice