nerdexam
CompTIA

CAS-002 · Question #607

A bank has just outsourced the security department to a consulting firm, but retained the security architecture group. A few months into the contract the bank discovers that the consulting firm has…

The correct answer is B. Ensure the consulting firm has service agreements with the sub-contractor; if the agreement. When a primary vendor sub-contracts work without explicit authorization, the client must ensure the primary vendor's contract flows down appropriate security and service requirements to the sub-contractor rather than creating a direct relationship or simply accepting the risk.

Integration of Computing, Communications and Business Disciplines

Question

A bank has just outsourced the security department to a consulting firm, but retained the security architecture group. A few months into the contract the bank discovers that the consulting firm has sub-contracted some of the security functions to another provider. Management is pressuring the sourcing manager to ensure adequate protections are in place to insulate the bank from legal and service exposures. Which of the following is the MOST appropriate action to take?

Options

  • ADirectly establish another separate service contract with the sub-contractor to limit the risk
  • BEnsure the consulting firm has service agreements with the sub-contractor; if the agreement
  • CLog it as a risk in the business risk register and pass the risk to the consulting firm for
  • DTerminate the contract immediately and bring the security department in-house again to

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    80% (16)
  • C
    5% (1)
  • D
    10% (2)

Why each option

When a primary vendor sub-contracts work without explicit authorization, the client must ensure the primary vendor's contract flows down appropriate security and service requirements to the sub-contractor rather than creating a direct relationship or simply accepting the risk.

ADirectly establish another separate service contract with the sub-contractor to limit the risk

Directly contracting with the sub-contractor creates a parallel legal relationship that bypasses the primary vendor's accountability and complicates governance without eliminating the original exposure.

BEnsure the consulting firm has service agreements with the sub-contractor; if the agreementCorrect

Ensuring the consulting firm has adequate service agreements with the sub-contractor preserves the chain of contractual accountability through the primary vendor, which is the correct governance structure for managed outsourcing arrangements. This approach holds the consulting firm responsible for their sub-contractor's performance and compliance, insulating the bank from direct legal exposure. Requiring flow-down contract terms ensures security and service standards are maintained throughout the supply chain without disrupting the primary vendor relationship.

CLog it as a risk in the business risk register and pass the risk to the consulting firm for

Logging the risk and passing it to the consulting firm without requiring contractual remediation does not provide the adequate protections management is demanding against legal and service exposures.

DTerminate the contract immediately and bring the security department in-house again to

Immediately terminating the contract and insourcing is a disproportionate response when contractual remediation options have not yet been pursued and the issue may be resolvable.

Concept tested: Third-party vendor contract governance and sub-contractor oversight

Source: https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/final

Topics

#third-party risk#outsourcing#contract management#vendor governance

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice