CRISC · Question #280
Which of the following observations from a third-party service provider review would be of GREATEST concern to a risk practitioner?
The correct answer is A. Service level agreements (SLAs) have not been met over the last quarter. The greatest concern from a third-party service provider review is consistent failure to meet Service Level Agreements (SLAs), as this directly impacts organizational operations and objectives.
Question
Which of the following observations from a third-party service provider review would be of GREATEST concern to a risk practitioner?
Options
- AService level agreements (SLAs) have not been met over the last quarter.
- BThe service contract is up for renewal in less than thirty days.
- CKey third-party personnel have recently been replaced.
- DMonthly service charges are significantly higher than industry norms.
How the community answered
(32 responses)- A66% (21)
- B9% (3)
- C22% (7)
- D3% (1)
Why each option
The greatest concern from a third-party service provider review is consistent failure to meet Service Level Agreements (SLAs), as this directly impacts organizational operations and objectives.
Consistent failure to meet SLAs directly signifies that the third-party provider is not delivering the agreed-upon level of service, which can lead to operational disruptions, increased risk exposure for the organization, and potential breaches of security, availability, or performance. This represents a direct and quantifiable failure of the service agreement.
A looming contract renewal is a logistical and contractual concern that requires planning, but it does not indicate an immediate failure in service delivery or increased risk exposure in the same way as unmet SLAs.
Replacement of key personnel can introduce uncertainty and potential risk, but it doesn't necessarily mean service quality has deteriorated or that risks are actively materializing, unlike a direct failure of SLAs.
Higher service charges are a financial concern affecting budget and cost-effectiveness, but they do not directly represent an increased *risk* to the organization's security or operational continuity.
Concept tested: Third-party risk management, SLA compliance
Source: https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.