CGEIT · Question #455
A business unit is planning to replace an existing IT legacy solution with a hosted Software as a Service (SaaS) solution. However, business management is concerned that stored data will be at risk. W
The correct answer is B. Include risk-related requirements in the SaaS contract.. When adopting a SaaS solution, the most effective way to reduce data risk is by contractually obligating the vendor to meet specific security requirements.
Question
A business unit is planning to replace an existing IT legacy solution with a hosted Software as a Service (SaaS) solution. However, business management is concerned that stored data will be at risk. Which of the following is the MOST effective way to reduce the risk associated with the SaaS solution?
Options
- AResearch the technology and identify potential security threats.
- BInclude risk-related requirements in the SaaS contract.
- CCreate key risk indicators (KRls) for the SaaS solution.
- DRedefine the risk appetite and risk tolerance.
How the community answered
(19 responses)- A5% (1)
- B79% (15)
- C11% (2)
- D5% (1)
Why each option
When adopting a SaaS solution, the most effective way to reduce data risk is by contractually obligating the vendor to meet specific security requirements.
Researching technology and identifying threats is an initial step, but it doesn't *reduce* the risk; it only identifies it.
Including risk-related requirements in the SaaS contract legally binds the provider to specific security measures, data protection standards, and incident response procedures. This approach proactively addresses concerns by embedding security into the service agreement and provides legal recourse if the provider fails to uphold their commitments.
Creating KRIs helps monitor risk levels over time, but it doesn't *reduce* the inherent risk of the data being at risk in the first place, nor does it enforce security controls.
Redefining risk appetite and tolerance changes the organization's acceptance level for risk, but it does not technically reduce the actual risk itself for the SaaS solution.
Concept tested: SaaS risk mitigation through contracts
Source: https://learn.microsoft.com/en-us/compliance/regulatory/offering-saas-security
Topics
Community Discussion
No community discussion yet for this question.