CGEIT · Question #506
Which of the following is the BEST way to manage the risk associated with outsourcing critical IT services?
The correct answer is B. Define controls within service level agreements (SLAs). The most effective way to manage risks from outsourced IT services is by embedding specific controls directly into the Service Level Agreements (SLAs) with the vendor. This contractual approach ensures that security and performance expectations are clearly defined and…
Question
Which of the following is the BEST way to manage the risk associated with outsourcing critical IT services?
Options
- AEnsure vendors hold information security certifications.
- BDefine controls within service level agreements (SLAs).
- CConduct quarterly performance reviews.
- DEnsure exit clauses are added to the contract.
How the community answered
(62 responses)- A23% (14)
- B60% (37)
- C6% (4)
- D11% (7)
Why each option
The most effective way to manage risks from outsourced IT services is by embedding specific controls directly into the Service Level Agreements (SLAs) with the vendor. This contractual approach ensures that security and performance expectations are clearly defined and enforceable.
Information security certifications demonstrate a vendor's general capability but do not guarantee specific controls or performance for *your* critical services, nor do they provide a direct enforcement mechanism for risk management in an ongoing operational context.
Defining controls within SLAs provides a legally binding framework for managing risks associated with critical outsourced IT services. SLAs specify the performance, availability, security, and other operational metrics that the vendor must adhere to, making non-compliance actionable and ensuring risk mitigation is contractually enforced.
Quarterly performance reviews are a monitoring activity, important for assessing adherence, but they do not establish or enforce the foundational controls necessary to manage risks in the first place.
Exit clauses are crucial for contingency planning and contract termination, but they do not actively manage or mitigate the operational risks of critical services *during* the contract's active period.
Concept tested: Outsourcing risk management via SLAs
Topics
Community Discussion
No community discussion yet for this question.