nerdexam
(ISC)2

CISSP · Question #555

Which of the following is held accountable for the risk to organizational systems and data that result from outsourcing Information Technology (IT) systems and services?

The correct answer is A. The acquiring organization. When an organization outsources IT systems or services, the acquiring (client) organization retains ultimate accountability for the risks to its own systems and data, even though a third-party provider performs the work.

Submitted by tyler.j· Mar 5, 2026Security and Risk Management

Question

Which of the following is held accountable for the risk to organizational systems and data that result from outsourcing Information Technology (IT) systems and services?

Options

  • AThe acquiring organization
  • BThe service provider
  • CThe risk executive (function)
  • DThe IT manager

How the community answered

(38 responses)
  • A
    74% (28)
  • B
    3% (1)
  • C
    16% (6)
  • D
    8% (3)

Why each option

When an organization outsources IT systems or services, the acquiring (client) organization retains ultimate accountability for the risks to its own systems and data, even though a third-party provider performs the work.

AThe acquiring organizationCorrect

The acquiring organization is the entity that owns the mission, data, and risk tolerance, and therefore cannot transfer accountability to an external provider. Per NIST SP 800-37 and supply chain risk management guidance, outsourcing shifts operational responsibility but not risk accountability - the organization that acquires the service remains responsible for ensuring adequate security controls are in place and for accepting residual risk.

BThe service provider

The service provider bears contractual and operational responsibility for delivering secure services, but legal and mission accountability for the risk to organizational assets remains with the acquiring organization, not the vendor.

CThe risk executive (function)

The risk executive (function) is an organizational role that coordinates risk management activities and ensures consistent risk decisions, but it does not bear ultimate accountability for risks introduced by outsourcing - the organization as a whole does.

DThe IT manager

The IT manager oversees day-to-day technology operations and may manage vendor relationships, but accountability for organizational risk from outsourcing decisions rests at the organizational level, not with an individual IT manager.

Concept tested: Organizational accountability for outsourced IT risk

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#outsourcing risk#third-party risk management#accountability#risk ownership

Community Discussion

No community discussion yet for this question.

Full CISSP Practice