CISM · Question #930
A third-party vendor is developing a mobile app for an organization's customers. Which of the following issues should be of GREATEST concern to the information security manager?
The correct answer is D. The contract has no data security requirements. Without data security requirements in the contract, the organization has no enforceable obligations for how customer data will be protected (controls, breach notification, privacy requirements, testing, retention, etc.), creating the greatest and most immediate third-party risk.
Question
A third-party vendor is developing a mobile app for an organization's customers. Which of the following issues should be of GREATEST concern to the information security manager?
Options
- AService level agreements (SLAs) after deployment are not defined.
- BThe mobile app's programmers are all offshore contractors.
- CThe vendor subcontracts its information security functions.
- DThe contract has no data security requirements.
How the community answered
(34 responses)- A9% (3)
- B35% (12)
- C15% (5)
- D41% (14)
Explanation
Without data security requirements in the contract, the organization has no enforceable obligations for how customer data will be protected (controls, breach notification, privacy requirements, testing, retention, etc.), creating the greatest and most immediate third-party risk.
Topics
Community Discussion
No community discussion yet for this question.