nerdexam
CompTIA

CAS-002 · Question #633

The company is about to upgrade a financial system through a third party, but wants to legally ensure that no sensitive information is compromised throughout the project. The project manager must…

The correct answer is A. Separation of duties E. NDA. Protecting sensitive data during a third-party engagement requires a legal confidentiality agreement, while limiting insider damage requires enforcing separation of duties.

Integration of Computing, Communications and Business Disciplines

Question

The company is about to upgrade a financial system through a third party, but wants to legally ensure that no sensitive information is compromised throughout the project. The project manager must also make sure that internal controls are set to mitigate the potential damage that one individual's actions may cause. Which of the following needs to be put in place to make certain both organizational requirements are met? (Select TWO).

Options

  • ASeparation of duties
  • BForensic tasks
  • CMOU
  • DOLA
  • ENDA
  • FJob rotation

How the community answered

(30 responses)
  • A
    83% (25)
  • B
    3% (1)
  • C
    3% (1)
  • F
    10% (3)

Why each option

Protecting sensitive data during a third-party engagement requires a legal confidentiality agreement, while limiting insider damage requires enforcing separation of duties.

ASeparation of dutiesCorrect

Separation of duties ensures no single individual has end-to-end control over a sensitive process, directly meeting the requirement to mitigate damage from one person's actions - for example, requiring two people to authorize financial transactions.

BForensic tasks

Forensic tasks are reactive investigative activities performed after an incident, not preventive legal or procedural controls.

CMOU

A Memorandum of Understanding (MOU) expresses a general intent to cooperate but is typically not legally binding and does not specifically protect sensitive data.

DOLA

An Operational Level Agreement (OLA) defines internal service delivery commitments between departments and does not address third-party confidentiality or insider threat mitigation.

ENDACorrect

A Non-Disclosure Agreement (NDA) is a legally binding contract that obligates the third party to protect sensitive information from unauthorized disclosure, directly satisfying the requirement to legally ensure no sensitive data is compromised during the project.

FJob rotation

Job rotation reduces fraud risk over time by cycling employees through roles, but it does not prevent a single individual from causing damage during the period they hold a given role.

Concept tested: Legal agreements and access control for third-party engagements

Source: https://csrc.nist.gov/glossary/term/separation_of_duty

Topics

#separation of duties#NDA#third-party risk#internal controls

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice