CRISC · Question #18
A company has recently acquired a customer relationship management (CRM) application from a certified software vendor. Which of the following will BE ST help lo prevent technical vulnerabilities from
The correct answer is B. Verity me software agreement indemnifies the company from losses. When using certified vendor software, verifying the software agreement indemnifies the company from losses is a key action to manage the financial risk associated with potential technical vulnerabilities being exploited.
Question
A company has recently acquired a customer relationship management (CRM) application from a certified software vendor. Which of the following will BE ST help lo prevent technical vulnerabilities from being exploded?
Options
- Aimplement code reviews and Quality assurance on a regular basis
- BVerity me software agreement indemnifies the company from losses
- CReview the source coda and error reporting of the application
- DUpdate the software with the latest patches and updates
How the community answered
(23 responses)- A22% (5)
- B61% (14)
- C4% (1)
- D13% (3)
Why each option
When using certified vendor software, verifying the software agreement indemnifies the company from losses is a key action to manage the financial risk associated with potential technical vulnerabilities being exploited.
Implementing code reviews and quality assurance on a regular basis is typically performed by the software vendor or for internally developed code, and is generally not feasible or appropriate for an organization acquiring COTS software from a certified vendor.
Verifying the software agreement indemnifies the company from losses helps to prevent the financial impact of technical vulnerabilities from harming the organization. While it does not technically prevent exploitation, it serves as a critical risk transfer mechanism, ensuring that the vendor bears responsibility for damages resulting from exploitable flaws in their certified software, thereby protecting the company's financial stability.
Reviewing the source code and error reporting of the application is typically not an option for COTS software from a vendor, as source code is rarely provided, and this activity falls within the vendor's development and quality assurance processes.
Updating the software with the latest patches and updates is a direct technical control to prevent exploitation of known vulnerabilities, but the question's chosen answer implies a focus on financial risk transfer rather than direct technical prevention.
Concept tested: Third-Party Software Risk Transfer
Topics
Community Discussion
No community discussion yet for this question.