nerdexam
CompTIA

CAS-002 · Question #240

The Chief Executive Officer (CEO) of a large prestigious enterprise has decided to reduce business costs by outsourcing to a third party company in another country. Functions to be outsourced…

The correct answer is D. Improper handling of customer data, loss of intellectual property and reputation damage. Outsourcing customer data processing and software development overseas without adequate controls most likely results in improper data handling, intellectual property loss, and reputation damage.

Integration of Computing, Communications and Business Disciplines

Question

The Chief Executive Officer (CEO) of a large prestigious enterprise has decided to reduce business costs by outsourcing to a third party company in another country. Functions to be outsourced include: business analysts, testing, software development and back office functions that deal with the processing of customer data. The Chief Risk Officer (CRO) is concerned about the outsourcing plans. Which of the following risks are MOST likely to occur if adequate controls are not implemented?

Options

  • AGeographical regulation issues, loss of intellectual property and interoperability agreement
  • BImproper handling of client data, interoperability agreement issues and regulatory issues
  • CCultural differences, increased cost of doing business and divestiture issues
  • DImproper handling of customer data, loss of intellectual property and reputation damage

How the community answered

(53 responses)
  • A
    4% (2)
  • B
    8% (4)
  • C
    17% (9)
  • D
    72% (38)

Why each option

Outsourcing customer data processing and software development overseas without adequate controls most likely results in improper data handling, intellectual property loss, and reputation damage.

AGeographical regulation issues, loss of intellectual property and interoperability agreement

Interoperability agreement issues are a technical integration concern and not a primary security or business risk arising directly from outsourcing customer data processing and development.

BImproper handling of client data, interoperability agreement issues and regulatory issues

Although improper client data handling and regulatory issues are valid risks, interoperability agreement issues are a less central concern than intellectual property loss and reputation damage in this outsourcing scenario.

CCultural differences, increased cost of doing business and divestiture issues

Cultural differences and divestiture issues are operational and strategic management concerns and are not among the most likely or most severe security risks from this type of offshore outsourcing arrangement.

DImproper handling of customer data, loss of intellectual property and reputation damageCorrect

Processing customer data offshore without controls exposes sensitive personal and financial information to improper handling; outsourcing software development creates direct risk of proprietary code and trade secret exfiltration; and any resulting data breach or compliance failure causes lasting damage to the enterprise's market reputation - these three risks are the most probable and highest-severity outcomes of the described outsourcing arrangement.

Concept tested: Third-party outsourcing security and intellectual property risk

Source: https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/final

Topics

#outsourcing risk#data privacy#intellectual property#regulatory compliance

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice