CAS-003 · Question #161
A company is in the process of outsourcing its customer relationship management system to a cloud provider. It will host the entire organization's customer database. The database will be accessed by…
The correct answer is C. Security clauses are implemented into the contract such as the right to audit. D. Review of the organizations security policies, procedures and relevant hosting certifications. Due diligence refers to an investigation of a business or person prior to signing a contract. Due diligence verifies information supplied by vendors with regards to processes, financials, experience, and performance. Due diligence should verify the data supplied in the RFP and…
Question
A company is in the process of outsourcing its customer relationship management system to a cloud provider. It will host the entire organization's customer database. The database will be accessed by both the company's users and its customers. The procurement department has asked what security activities must be performed for the deal to proceed. Which of the following are the MOST appropriate security activities to be performed as part of due diligence? (Select TWO).
Options
- APhysical penetration test of the datacenter to ensure there are appropriate controls.
- BPenetration testing of the solution to ensure that the customer data is well protected.
- CSecurity clauses are implemented into the contract such as the right to audit.
- DReview of the organizations security policies, procedures and relevant hosting certifications.
- ECode review of the solution to ensure that there are no back doors located in the software.
How the community answered
(23 responses)- A4% (1)
- B4% (1)
- C78% (18)
- E13% (3)
Explanation
Due diligence refers to an investigation of a business or person prior to signing a contract. Due diligence verifies information supplied by vendors with regards to processes, financials, experience, and performance. Due diligence should verify the data supplied in the RFP and concentrate on the following: Company profile, strategy, mission, and reputation Financial status, including reviews of audited financial statements Customer references, preferably from companies that have outsourced similar processes Management qualifications, including criminal background checks Process expertise, methodology, and effectiveness Quality initiatives and certifications Technology, infrastructure stability, and applications Security and audit controls Legal and regulatory compliance, including any outstanding complaints or litigation Use of Disaster recovery and business continuity policies C and D form part of Security and audit controls.
Topics
Community Discussion
No community discussion yet for this question.