nerdexam
CompTIA

CAS-003 · Question #521

An infrastructure team within an energy organization is at the end of a procurement process and has selected a vendor's SaaS platform to deliver services. As part of the legal negotiation, there are…

The correct answer is B. Require a solution owner within the energy organization to accept the identified risks and. Requiring a solution owner within the energy organization to formally accept the identified risks (B) is the appropriate next step. The two outstanding risks-data retention period alignment and geographical hosting-are real but limited in impact given that only a small number…

Risk Management

Question

An infrastructure team within an energy organization is at the end of a procurement process and has selected a vendor's SaaS platform to deliver services. As part of the legal negotiation, there are a number of outstanding risks, including: 1. There are clauses that confirm a data retention period in line with what is in the energy organization's security policy. 2. The data will be hosted and managed outside of the energy organization's geographical location. The number of users accessing the system will be small, and no sensitive data will be hosted in the SaaS platform. Which of the following should the project's security consultant recommend as the NEXT step?

Options

  • ADevelop a security exemption, as the solution does not meet the security policies of the energy
  • BRequire a solution owner within the energy organization to accept the identified risks and
  • CMititgate the risks by asking the vendor to accept the in-country privacy principles and modify the
  • DReview the procurement process to determine the lessons learned in relation to discovering risks

How the community answered

(31 responses)
  • A
    26% (8)
  • B
    58% (18)
  • C
    6% (2)
  • D
    10% (3)

Explanation

Requiring a solution owner within the energy organization to formally accept the identified risks (B) is the appropriate next step. The two outstanding risks-data retention period alignment and geographical hosting-are real but limited in impact given that only a small number of users will access the system and no sensitive data will be hosted in the SaaS platform. Since procurement is essentially complete and the risk profile is low, the correct governance action is formal risk acceptance by an authorized stakeholder, which creates accountability and an audit trail. Issuing a security exemption (A) treats the situation as a policy violation requiring formal override, which is disproportionate. Asking the vendor to modify the contract (C) would be appropriate if the risks were unacceptable. Reviewing the procurement process for lessons learned (D) is a retrospective action, not the immediate next step.

Topics

#SaaS risk management#risk acceptance#vendor management#data residency

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice