nerdexam
CompTIA

CAS-002 · Question #660

Company ABC is planning to outsource its Customer Relationship Management system (CRM) and marketing / leads management to Company XYZ. Which of the following is the MOST important to be considered…

The correct answer is C. Ensure there are security controls within the contract and the right to audit. Before outsourcing a critical system like a CRM, the most important step is ensuring the contract contains defined security controls and a right-to-audit clause to enforce ongoing vendor accountability.

Integration of Computing, Communications and Business Disciplines

Question

Company ABC is planning to outsource its Customer Relationship Management system (CRM) and marketing / leads management to Company XYZ. Which of the following is the MOST important to be considered before going ahead with the service?

Options

  • AInternal auditors have approved the outsourcing arrangement.
  • BPenetration testing can be performed on the externally facing web system.
  • CEnsure there are security controls within the contract and the right to audit.
  • DA physical site audit is performed on Company XYZ's management / operation.

How the community answered

(51 responses)
  • A
    6% (3)
  • B
    2% (1)
  • C
    90% (46)
  • D
    2% (1)

Why each option

Before outsourcing a critical system like a CRM, the most important step is ensuring the contract contains defined security controls and a right-to-audit clause to enforce ongoing vendor accountability.

AInternal auditors have approved the outsourcing arrangement.

Internal auditor approval addresses internal governance but does not create any binding security obligations on Company XYZ or provide ongoing oversight of their practices.

BPenetration testing can be performed on the externally facing web system.

Penetration testing on the external web system is a useful point-in-time assessment but does not establish enforceable ongoing security obligations or contractual accountability for the vendor.

CEnsure there are security controls within the contract and the right to audit.Correct

Embedding security controls and a right-to-audit provision in the contract is foundational to third-party risk management because it legally obligates the vendor to maintain defined security standards and grants the organization the ability to verify compliance at any time. Without these contractual provisions, the organization has no enforceable mechanism to ensure Company XYZ adequately protects customer data and business processes entrusted to them.

DA physical site audit is performed on Company XYZ's management / operation.

A physical site audit provides a snapshot of current security posture but does not create legally binding ongoing obligations or guarantee the right to conduct future audits as circumstances change.

Concept tested: Third-party risk management and right-to-audit contractual controls

Source: https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/final

Topics

#outsourcing#vendor management#right to audit#contract security

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice