nerdexam
CompTIA

CAS-003 · Question #535

An infrastructure team is at the end of a procurement process and has selected a vendor. As part of the final negotiation, there are a number of outstanding issues, including: 1. Indemnity clauses…

The correct answer is B. Require the solution owner to accept the identified risks and consequences. The security consultant's role is to identify and communicate risks, not to make the business decision. The risks have already been identified: capped liability and offshore data hosting. Because no sensitive data will be hosted and the user count is small, the risk profile is…

Risk Management

Question

An infrastructure team is at the end of a procurement process and has selected a vendor. As part of the final negotiation, there are a number of outstanding issues, including: 1. Indemnity clauses have identified the maximum liability. 2. The data will be hosted and managed outside of the company's geographical location. The number of users accessing the system will be small, and no sensitive data will be hosted in the solution. As the security consultant of the project, which of the following should the project's security consultant recommend as the NEXT step?

Options

  • ADevelop a security exemption, as it does not meet the security policies.
  • BRequire the solution owner to accept the identified risks and consequences.
  • CMitigate the risk by asking the vendor to accept the in-country privacy principles.
  • DReview the procurement process to determine the lessons learned.

How the community answered

(50 responses)
  • A
    20% (10)
  • B
    66% (33)
  • C
    4% (2)
  • D
    10% (5)

Explanation

The security consultant's role is to identify and communicate risks, not to make the business decision. The risks have already been identified: capped liability and offshore data hosting. Because no sensitive data will be hosted and the user count is small, the risk profile is relatively low, making a formal security exemption (A) disproportionate. Asking the vendor to accept in-country privacy principles (C) is unnecessary when no sensitive data is involved. Reviewing procurement for lessons learned (D) is a post-project activity. The appropriate next step is for the solution owner - the business stakeholder making the procurement decision - to formally accept the identified residual risks in writing, establishing accountability and completing the risk treatment process.

Topics

#vendor risk management#risk acceptance#data sovereignty#procurement security

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice