nerdexam
CompTIA

CAS-002 · Question #92

A financial institution has decided to purchase a very expensive resource management system and has selected the product and vendor. The vendor is experiencing some minor, but public, legal issues…

The correct answer is A. Include a source code escrow clause in the contract for this system. A source code escrow clause protects the purchaser by ensuring access to the vendor's source code if the vendor ceases operations, allowing the organization to maintain or transfer the software.

Integration of Computing, Communications and Business Disciplines

Question

A financial institution has decided to purchase a very expensive resource management system and has selected the product and vendor. The vendor is experiencing some minor, but public, legal issues. Senior management has some concerns on maintaining this system should the vendor go out of business. Which of the following should the Chief Information Security Officer (CISO) recommend to BEST limit exposure?

Options

  • AInclude a source code escrow clause in the contract for this system.
  • BRequire proof-of-insurance by the vendor in the RFP for this system.
  • CInclude a penalty clause in the contract for this system.
  • DRequire on-going maintenance as part of the SLA for this system.

How the community answered

(23 responses)
  • A
    70% (16)
  • B
    4% (1)
  • C
    17% (4)
  • D
    9% (2)

Why each option

A source code escrow clause protects the purchaser by ensuring access to the vendor's source code if the vendor ceases operations, allowing the organization to maintain or transfer the software.

AInclude a source code escrow clause in the contract for this system.Correct

A source code escrow agreement requires the vendor to deposit source code with a neutral third party, which is released to the purchaser under defined trigger conditions such as vendor bankruptcy or dissolution. This directly addresses management continuity concerns by ensuring the financial institution can maintain, modify, or migrate the system even if the vendor no longer exists.

BRequire proof-of-insurance by the vendor in the RFP for this system.

Proof-of-insurance protects against financial liability from vendor errors or negligence but does not ensure the organization can maintain the software if the vendor goes out of business.

CInclude a penalty clause in the contract for this system.

A penalty clause provides financial recourse for contract breaches but offers no practical mechanism to maintain the system if the vendor ceases to exist.

DRequire on-going maintenance as part of the SLA for this system.

Ongoing maintenance in an SLA is unenforceable and meaningless if the vendor goes out of business, as there is no longer an entity to fulfill the obligation.

Concept tested: Source code escrow for vendor continuity risk mitigation

Source: https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/final

Topics

#source code escrow#vendor risk#third-party contracts#business continuity

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice