nerdexam
Isaca

CRISC · Question #429

An organization has outsourced its backup and recovery procedures to a third-party cloud provider. Which of the following should be the risk practitioner's NEXT course of action?

The correct answer is C. Review the contract and service level agreements (SLAs).. When outsourcing backup and recovery, the risk practitioner's immediate next step should be to thoroughly review the contract and Service Level Agreements (SLAs) with the third-party provider.

Submitted by haruto_sh· Apr 18, 2026Governance

Question

An organization has outsourced its backup and recovery procedures to a third-party cloud provider. Which of the following should be the risk practitioner's NEXT course of action?

Options

  • ARemove the associated risk from the register.
  • BValidate control effectiveness and update the risk register.
  • CReview the contract and service level agreements (SLAs).
  • DObtain an assurance report from the third-party provider.

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    11% (4)
  • C
    80% (28)
  • D
    3% (1)

Why each option

When outsourcing backup and recovery, the risk practitioner's immediate next step should be to thoroughly review the contract and Service Level Agreements (SLAs) with the third-party provider.

ARemove the associated risk from the register.

Outsourcing transfers certain risks to the provider but does not eliminate all associated risks; the organization still retains responsibility for vendor oversight and residual risks.

BValidate control effectiveness and update the risk register.

Validating control effectiveness and updating the risk register are essential follow-up steps, but they cannot be properly executed without first understanding the specific contractual obligations and expectations set forth.

CReview the contract and service level agreements (SLAs).Correct

Before any other actions, the risk practitioner must review the contract and SLAs to understand the legal and operational commitments of the third-party provider regarding backup and recovery, including responsibilities, performance metrics, and liabilities. This critical step clarifies the boundaries of transferred risk and establishes the basis for all future validation and monitoring activities.

DObtain an assurance report from the third-party provider.

Obtaining an assurance report (e.g., SOC 2) is a crucial step for vendor risk management, but it should logically follow the review of the contract and SLAs to ensure the report adequately covers the agreed-upon services and controls.

Concept tested: Third-party risk management (contract review)

Source: https://learn.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-governance-strategy-risk-management#gv-11-manage-third-party-risk

Topics

#Outsourcing risk#Third-party risk management#Contract review#Service Level Agreements (SLAs)

Community Discussion

No community discussion yet for this question.

Full CRISC Practice