CAS-003 · Question #373
The Chief Executive Officer (CEO) of a small startup company has an urgent need for a security policy and assessment to address governance, risk management, and compliance. The company has a…
The correct answer is C. Release an RFP to consultancy firms, and then select the most appropriate consultant who can. Releasing an RFP (Request for Proposal) to external consultancy firms is the most cost-effective approach given the constraints: no in-house security staff, a resource-limited IT team, a tight three-month deadline, and a startup budget. Consultants bring immediate, specialized…
Question
The Chief Executive Officer (CEO) of a small startup company has an urgent need for a security policy and assessment to address governance, risk management, and compliance. The company has a resource- constrained IT department, but has no information security staff. The CEO has asked for this to be completed in three months. Which of the following would be the MOST cost-effective solution to meet the company's needs?
Options
- ASelect one of the IT personnel to obtain information security training, and then develop all
- BAccept all risks associated with information security, and then bring up the issue again at next
- CRelease an RFP to consultancy firms, and then select the most appropriate consultant who can
- DHire an experienced, full-time information security team to run the startup company's information
How the community answered
(46 responses)- A7% (3)
- B13% (6)
- C76% (35)
- D4% (2)
Explanation
Releasing an RFP (Request for Proposal) to external consultancy firms is the most cost-effective approach given the constraints: no in-house security staff, a resource-limited IT team, a tight three-month deadline, and a startup budget. Consultants bring immediate, specialized expertise in governance frameworks (NIST, ISO 27001, SOC 2) without the long-term overhead of full-time salaries and benefits. An RFP process also allows the company to select the best value offering. Option A (training an existing IT person) is problematic because building competency takes much longer than three months and the quality of the resulting policy may be insufficient for real compliance needs. Option B (accepting all risks) is irresponsible and fails to meet the stated GRC requirement - it creates liability without any mitigation. Option D (hiring a full-time security team) is the most expensive option and not justified for a startup with no existing security program, especially under a cost-effectiveness constraint.
Topics
Community Discussion
No community discussion yet for this question.