CAS-002 · Question #335
A company is in the process of outsourcing its customer relationship management system to a cloud provider. It will host the entire organization's customer database. The database will be accessed by…
The correct answer is C. Security clauses are implemented into the contract such as the right to audit. D. Review of the organizations security policies, procedures and relevant hosting certifications. Due diligence for cloud outsourcing focuses on reviewing existing documentation, certifications, and establishing contractual security obligations rather than performing active technical assessments of the provider's systems.
Question
A company is in the process of outsourcing its customer relationship management system to a cloud provider. It will host the entire organization's customer database. The database will be accessed by both the company's users and its customers. The procurement department has asked what security activities must be performed for the deal to proceed. Which of the following are the MOST appropriate security activities to be performed as part of due diligence? (Select TWO).
Options
- APhysical penetration test of the datacenter to ensure there are appropriate controls.
- BPenetration testing of the solution to ensure that the customer data is well protected.
- CSecurity clauses are implemented into the contract such as the right to audit.
- DReview of the organizations security policies, procedures and relevant hosting certifications.
- ECode review of the solution to ensure that there are no back doors located in the software.
How the community answered
(23 responses)- A9% (2)
- B17% (4)
- C70% (16)
- E4% (1)
Why each option
Due diligence for cloud outsourcing focuses on reviewing existing documentation, certifications, and establishing contractual security obligations rather than performing active technical assessments of the provider's systems.
Physical penetration testing of a cloud provider's datacenter is not a standard due diligence activity; physical security is typically validated through third-party audits and certifications rather than direct testing, which providers rarely permit.
Active penetration testing of the solution is a due care activity performed after the engagement is established, not a procurement-stage due diligence review activity.
Inserting security clauses such as the right to audit into the contract is a foundational due diligence activity that provides the company with ongoing legal visibility and recourse into the cloud provider's security practices throughout the relationship.
Reviewing the provider's security policies, procedures, and hosting certifications such as ISO 27001 or SOC 2 is a core due diligence step that validates the provider meets required security standards before the organization commits contractually.
Source code review for back doors is an invasive active assessment activity, not a due diligence review; cloud providers do not typically grant access to proprietary source code during vendor evaluation.
Concept tested: Due diligence activities during cloud service provider procurement
Source: https://cloudsecurityalliance.org/research/guidance
Topics
Community Discussion
No community discussion yet for this question.