SY0-301 · Question #905
Acme Corp has selectively outsourced proprietary business processes to ABC Services. Due to some technical issues, ABC services wants to send some of Acme Corp's debug data to a third party vendor…
The correct answer is C. This may violate data ownership and non-disclosure agreements. When a vendor wants to share a client's data with a sub-vendor, the original contractual agreements governing data ownership and confidentiality must be reviewed first.
Question
Acme Corp has selectively outsourced proprietary business processes to ABC Services. Due to some technical issues, ABC services wants to send some of Acme Corp's debug data to a third party vendor for problem resolution. Which of the following MUST be considered prior to sending data to a third party?
Options
- AThe data should be encrypted prior to transport
- BThis would not constitute unauthorized data sharing
- CThis may violate data ownership and non-disclosure agreements
- DAcme Corp should send the data to ABC Services' vendor instead
How the community answered
(35 responses)- A14% (5)
- B3% (1)
- C74% (26)
- D9% (3)
Why each option
When a vendor wants to share a client's data with a sub-vendor, the original contractual agreements governing data ownership and confidentiality must be reviewed first.
Encrypting data in transit is a security best practice but does not address the underlying legal question of whether sharing the data with a third party is permitted at all.
Sharing a client's proprietary data with an unauthorized third party without explicit permission can absolutely constitute unauthorized data sharing under most contractual and regulatory frameworks.
Outsourcing agreements typically include non-disclosure agreements (NDAs) and data ownership clauses that restrict how the primary vendor can handle or share the client's data. Forwarding Acme Corp's debug data to a third party without Acme Corp's consent could violate these contractual obligations. This constitutes a legal and compliance concern that must be addressed before any data transfer occurs.
Having Acme Corp send the data directly does not resolve the core issue of whether the third-party disclosure is permissible under the existing agreements.
Concept tested: Third-party data sharing and NDA compliance
Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
Topics
Community Discussion
No community discussion yet for this question.