CAS-002 · Question #607
A bank has just outsourced the security department to a consulting firm, but retained the security architecture group. A few months into the contract the bank discovers that the consulting firm has…
The correct answer is B. Ensure the consulting firm has service agreements with the sub-contractor; if the agreement. When a primary vendor sub-contracts work without explicit authorization, the client must ensure the primary vendor's contract flows down appropriate security and service requirements to the sub-contractor rather than creating a direct relationship or simply accepting the risk.
Question
A bank has just outsourced the security department to a consulting firm, but retained the security architecture group. A few months into the contract the bank discovers that the consulting firm has sub-contracted some of the security functions to another provider. Management is pressuring the sourcing manager to ensure adequate protections are in place to insulate the bank from legal and service exposures. Which of the following is the MOST appropriate action to take?
Options
- ADirectly establish another separate service contract with the sub-contractor to limit the risk
- BEnsure the consulting firm has service agreements with the sub-contractor; if the agreement
- CLog it as a risk in the business risk register and pass the risk to the consulting firm for
- DTerminate the contract immediately and bring the security department in-house again to
How the community answered
(20 responses)- A5% (1)
- B80% (16)
- C5% (1)
- D10% (2)
Why each option
When a primary vendor sub-contracts work without explicit authorization, the client must ensure the primary vendor's contract flows down appropriate security and service requirements to the sub-contractor rather than creating a direct relationship or simply accepting the risk.
Directly contracting with the sub-contractor creates a parallel legal relationship that bypasses the primary vendor's accountability and complicates governance without eliminating the original exposure.
Ensuring the consulting firm has adequate service agreements with the sub-contractor preserves the chain of contractual accountability through the primary vendor, which is the correct governance structure for managed outsourcing arrangements. This approach holds the consulting firm responsible for their sub-contractor's performance and compliance, insulating the bank from direct legal exposure. Requiring flow-down contract terms ensures security and service standards are maintained throughout the supply chain without disrupting the primary vendor relationship.
Logging the risk and passing it to the consulting firm without requiring contractual remediation does not provide the adequate protections management is demanding against legal and service exposures.
Immediately terminating the contract and insourcing is a disproportionate response when contractual remediation options have not yet been pursued and the issue may be resolvable.
Concept tested: Third-party vendor contract governance and sub-contractor oversight
Source: https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.