CAS-003 · Question #923
A line-of-business manager has deeded in conjunction with the IT and legal departments, that outsourcing a specific function to a third-party vendor would be the best course of action for the…
The correct answer is E. Risk assessment. Before the CSO signs off on a third-party vendor relationship, a Risk Assessment must be performed. A risk assessment is the foundational step that identifies, analyzes, and evaluates all risks the vendor relationship introduces-including data security, regulatory compliance…
Question
A line-of-business manager has deeded in conjunction with the IT and legal departments, that outsourcing a specific function to a third-party vendor would be the best course of action for the business to increase efficiency and profit. Which of the following should the Chief Security Officer (CSO) perform before signing off on the third-party vendor?
Options
- ASupply chain audit
- BVulnerability assessment
- CPenetration test
- DApplication code review
- ERisk assessment
How the community answered
(25 responses)- A4% (1)
- C4% (1)
- E92% (23)
Explanation
Before the CSO signs off on a third-party vendor relationship, a Risk Assessment must be performed. A risk assessment is the foundational step that identifies, analyzes, and evaluates all risks the vendor relationship introduces-including data security, regulatory compliance (GDPR, HIPAA, etc.), supply chain risk, operational dependencies, and the vendor's own security posture. It determines whether residual risk is acceptable given the business benefit and informs contract terms like SLAs, right-to-audit clauses, and data handling requirements. The other options may be components that feed into a risk assessment: a supply chain audit (A) is a subset activity; a vulnerability assessment (B) or penetration test (C) may be required of the vendor; an application code review (D) is relevant only if the vendor delivers software. The risk assessment is the overarching process that drives the decision.
Topics
Community Discussion
No community discussion yet for this question.