CAS-002 · Question #92
A financial institution has decided to purchase a very expensive resource management system and has selected the product and vendor. The vendor is experiencing some minor, but public, legal issues…
The correct answer is A. Include a source code escrow clause in the contract for this system. A source code escrow clause protects the purchaser by ensuring access to the vendor's source code if the vendor ceases operations, allowing the organization to maintain or transfer the software.
Question
A financial institution has decided to purchase a very expensive resource management system and has selected the product and vendor. The vendor is experiencing some minor, but public, legal issues. Senior management has some concerns on maintaining this system should the vendor go out of business. Which of the following should the Chief Information Security Officer (CISO) recommend to BEST limit exposure?
Options
- AInclude a source code escrow clause in the contract for this system.
- BRequire proof-of-insurance by the vendor in the RFP for this system.
- CInclude a penalty clause in the contract for this system.
- DRequire on-going maintenance as part of the SLA for this system.
How the community answered
(23 responses)- A70% (16)
- B4% (1)
- C17% (4)
- D9% (2)
Why each option
A source code escrow clause protects the purchaser by ensuring access to the vendor's source code if the vendor ceases operations, allowing the organization to maintain or transfer the software.
A source code escrow agreement requires the vendor to deposit source code with a neutral third party, which is released to the purchaser under defined trigger conditions such as vendor bankruptcy or dissolution. This directly addresses management continuity concerns by ensuring the financial institution can maintain, modify, or migrate the system even if the vendor no longer exists.
Proof-of-insurance protects against financial liability from vendor errors or negligence but does not ensure the organization can maintain the software if the vendor goes out of business.
A penalty clause provides financial recourse for contract breaches but offers no practical mechanism to maintain the system if the vendor ceases to exist.
Ongoing maintenance in an SLA is unenforceable and meaningless if the vendor goes out of business, as there is no longer an entity to fulfill the obligation.
Concept tested: Source code escrow for vendor continuity risk mitigation
Source: https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.