CISM · Question #86
An organization learns that a third party has outsourced critical functions to another external provider. Which of the following is the information security manager's MOST important course of action?
The correct answer is D. Evaluate the third party's agreements with its external provider.. When a third party subcontracts critical functions, the information security manager must primarily evaluate the terms of the third party's agreements with its sub-provider to ensure adequate security and compliance.
Question
An organization learns that a third party has outsourced critical functions to another external provider. Which of the following is the information security manager's MOST important course of action?
Options
- AEngage an independent audit of the third party's external provider.
- BConduct an external audit of the contracted third party.
- CRecommend canceling the contract with the third party.
- DEvaluate the third party's agreements with its external provider.
How the community answered
(43 responses)- A7% (3)
- B2% (1)
- C9% (4)
- D81% (35)
Why each option
When a third party subcontracts critical functions, the information security manager must primarily evaluate the terms of the third party's agreements with its sub-provider to ensure adequate security and compliance.
Engaging an independent audit of the sub-provider might be a later step, but the most important initial action is to understand the contractual obligations and existing controls.
An external audit of the contracted third party would address their controls, but it doesn't directly address the new risk introduced by their sub-contracting of critical functions.
Recommending canceling the contract is an extreme measure without first understanding the implications and contractual obligations of the sub-contracting.
Evaluating the third party's agreements with its external provider is crucial because it ensures that the original security and compliance requirements stipulated in the primary contract are flowed down and appropriately addressed by the sub-contractor. This due diligence ensures the organization's risks are managed even through multi-tiered outsourcing.
Concept tested: Third-party risk management and sub-contractor oversight
Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
Topics
Community Discussion
No community discussion yet for this question.