CISSP · Question #555
Which of the following is held accountable for the risk to organizational systems and data that result from outsourcing Information Technology (IT) systems and services?
The correct answer is A. The acquiring organization. When an organization outsources IT systems or services, the acquiring (client) organization retains ultimate accountability for the risks to its own systems and data, even though a third-party provider performs the work.
Question
Options
- AThe acquiring organization
- BThe service provider
- CThe risk executive (function)
- DThe IT manager
How the community answered
(38 responses)- A74% (28)
- B3% (1)
- C16% (6)
- D8% (3)
Why each option
When an organization outsources IT systems or services, the acquiring (client) organization retains ultimate accountability for the risks to its own systems and data, even though a third-party provider performs the work.
The acquiring organization is the entity that owns the mission, data, and risk tolerance, and therefore cannot transfer accountability to an external provider. Per NIST SP 800-37 and supply chain risk management guidance, outsourcing shifts operational responsibility but not risk accountability - the organization that acquires the service remains responsible for ensuring adequate security controls are in place and for accepting residual risk.
The service provider bears contractual and operational responsibility for delivering secure services, but legal and mission accountability for the risk to organizational assets remains with the acquiring organization, not the vendor.
The risk executive (function) is an organizational role that coordinates risk management activities and ensures consistent risk decisions, but it does not bear ultimate accountability for risks introduced by outsourcing - the organization as a whole does.
The IT manager oversees day-to-day technology operations and may manage vendor relationships, but accountability for organizational risk from outsourcing decisions rests at the organizational level, not with an individual IT manager.
Concept tested: Organizational accountability for outsourced IT risk
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.