CAS-003 · Question #864
A line-of-business manager has decided, in conjunction with the IT and legal departments, that outsourcing a specific function to a third-party vendor would be the best course of action for the…
The correct answer is E. Risk assessment. Before approving a third-party vendor arrangement, the CSO's primary responsibility is to understand the risk the relationship introduces to the organization. A risk assessment identifies, evaluates, and prioritizes risks across security, compliance, operational continuity, and…
Question
A line-of-business manager has decided, in conjunction with the IT and legal departments, that outsourcing a specific function to a third-party vendor would be the best course of action for the business to increase efficiency and profit. Which of the following should the Chief Security Officer (CSO) perform before signing off on the third-party vendor?
Options
- ASupply chain audit
- BVulnerability assessment
- CPenetration test
- DApplication code review
- ERisk assessment
How the community answered
(31 responses)- B3% (1)
- C6% (2)
- D3% (1)
- E87% (27)
Explanation
Before approving a third-party vendor arrangement, the CSO's primary responsibility is to understand the risk the relationship introduces to the organization. A risk assessment identifies, evaluates, and prioritizes risks across security, compliance, operational continuity, and data protection dimensions specific to that vendor. A supply chain audit (A) is narrower and focuses on the vendor's own supply chain integrity. A vulnerability assessment (B) or penetration test (C) are technical evaluations of systems, not vendor risk. An application code review (D) examines software quality but doesn't address the broader security posture or contractual/compliance risks of the relationship. The risk assessment provides the comprehensive view needed before sign-off.
Topics
Community Discussion
No community discussion yet for this question.