CISSP · Question #1153
When network management is outsourced to third parties, which of the following is the MOST effective method of protecting critical data assets?
The correct answer is C. Employ strong access controls. When outsourcing network management, strong access controls are the most effective technical safeguard because they directly limit and govern what third parties can access, modify, or exfiltrate from critical systems.
Question
Options
- AProvide links to security policies
- BLog all activities associated with sensitive systems
- CEmploy strong access controls
- DConfirm that confidentiality agreements are signed
How the community answered
(39 responses)- A13% (5)
- B8% (3)
- C54% (21)
- D26% (10)
Why each option
When outsourcing network management, strong access controls are the most effective technical safeguard because they directly limit and govern what third parties can access, modify, or exfiltrate from critical systems.
Providing links to security policies is an administrative awareness measure that does not technically enforce or restrict third-party access to critical systems.
Logging all activities is a detective control that identifies incidents after they occur but does not prevent unauthorized access or data exfiltration in the first place.
Strong access controls-such as role-based access control (RBAC), least privilege, multi-factor authentication, and network segmentation-directly prevent unauthorized access to critical data assets by third parties. These controls enforce boundaries at the technical level, ensuring outsourced administrators can only reach systems and data necessary for their specific tasks. Unlike administrative or detective measures, access controls are proactive and preventive, making them the most effective protection method.
Confidentiality agreements are legal and contractual controls that create accountability but provide no technical enforcement mechanism to prevent a third party from accessing or misusing sensitive data.
Concept tested: Third-party risk management and access control enforcement
Source: https://www.nist.gov/publications/nist-special-publication-800-53-revision-5
Topics
Community Discussion
No community discussion yet for this question.