CRISC · Question #429
An organization has outsourced its backup and recovery procedures to a third-party cloud provider. Which of the following should be the risk practitioner's NEXT course of action?
The correct answer is C. Review the contract and service level agreements (SLAs).. When outsourcing backup and recovery, the risk practitioner's immediate next step should be to thoroughly review the contract and Service Level Agreements (SLAs) with the third-party provider.
Question
An organization has outsourced its backup and recovery procedures to a third-party cloud provider. Which of the following should be the risk practitioner's NEXT course of action?
Options
- ARemove the associated risk from the register.
- BValidate control effectiveness and update the risk register.
- CReview the contract and service level agreements (SLAs).
- DObtain an assurance report from the third-party provider.
How the community answered
(35 responses)- A6% (2)
- B11% (4)
- C80% (28)
- D3% (1)
Why each option
When outsourcing backup and recovery, the risk practitioner's immediate next step should be to thoroughly review the contract and Service Level Agreements (SLAs) with the third-party provider.
Outsourcing transfers certain risks to the provider but does not eliminate all associated risks; the organization still retains responsibility for vendor oversight and residual risks.
Validating control effectiveness and updating the risk register are essential follow-up steps, but they cannot be properly executed without first understanding the specific contractual obligations and expectations set forth.
Before any other actions, the risk practitioner must review the contract and SLAs to understand the legal and operational commitments of the third-party provider regarding backup and recovery, including responsibilities, performance metrics, and liabilities. This critical step clarifies the boundaries of transferred risk and establishes the basis for all future validation and monitoring activities.
Obtaining an assurance report (e.g., SOC 2) is a crucial step for vendor risk management, but it should logically follow the review of the contract and SLAs to ensure the report adequately covers the agreed-upon services and controls.
Concept tested: Third-party risk management (contract review)
Source: https://learn.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-governance-strategy-risk-management#gv-11-manage-third-party-risk
Topics
Community Discussion
No community discussion yet for this question.