CAS-002 · Question #170
Several business units have requested the ability to use collaborative web-based meeting places with third party vendors. Generally these require user registration, installation of client-based…
The correct answer is D. Evaluate several meeting providers. When business units need third-party web collaboration tools, evaluating multiple providers allows the organization to select one that balances functionality with security requirements before any deployment.
Question
Several business units have requested the ability to use collaborative web-based meeting places with third party vendors. Generally these require user registration, installation of client-based ActiveX or Java applets, and also the ability for the user to share their desktop in read-only or read-write mode. In order to ensure that information security is not compromised, which of the following controls is BEST suited to this situation?
Options
- ADisallow the use of web-based meetings as this could lead to vulnerable client-side
- BHire an outside consultant firm to perform both a quantitative and a qualitative risk-based
- CAllow the use of web-based meetings, but put controls in place to ensure that the use of
- DEvaluate several meeting providers.
How the community answered
(42 responses)- A19% (8)
- B5% (2)
- C10% (4)
- D67% (28)
Why each option
When business units need third-party web collaboration tools, evaluating multiple providers allows the organization to select one that balances functionality with security requirements before any deployment.
Disallowing web-based meetings entirely fails to meet the stated business need and applies an overly restrictive control that does not balance security with business requirements.
Hiring a consultant for a risk assessment is a supporting activity, not the primary control, and does not directly address selection and governance of a meeting platform.
Allowing meetings with unspecified controls is premature without first evaluating providers to understand the specific risks and which controls are actually applicable.
Evaluating several meeting providers allows the organization to compare security features, compliance certifications, and risk profiles before committing to a solution. This due-diligence approach ensures the chosen platform meets both the business need for collaboration and the organization's information security requirements. It avoids both the extreme of outright prohibition and the risk of deploying an unvetted tool.
Concept tested: Third-party service security evaluation and vendor risk management
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-161.pdf
Topics
Community Discussion
No community discussion yet for this question.