Question

Difficulty: HardThird-Party Risk Management and Supply Chain Oversight

An organization is preparing to engage a third-party managed service provider (MSP) to handle sensitive customer data archiving and off-site backup management. As part of the enterprise third-party risk management (TPRM) governance program, the security team must implement controls that verify operational effectiveness over time and guarantee access for compliance verification. Which TWO of the following requirements should be included in the vendor oversight framework?

  1. Incorporate a Right-to-Audit clause in the contract to ensure the enterprise or designated third parties can evaluate the vendor's security controlsAnswer
  2. B
    Require the vendor to execute an Interconnection Security Agreement (ISA) to establish physical security boundaries at the vendor's backup site
  3. Require continuous receipt of independent SOC 2 Type II audit reports to verify the operational effectiveness of vendor controls over an extended evaluation periodAnswer
  4. D
    Deploy network-level inline intrusion prevention sensors within the vendor's internal database network to enforce data access policies
  5. E
    Substitute annual vendor risk assessments with bi-weekly external vulnerability port scans against the vendor's public IP infrastructure

Answer

The organization should incorporate a contractual Right-to-Audit clause and require continuous receipt of independent SOC 2 Type II audit reports to ensure third-party risk oversight.
Effective third-party risk oversight requires both legal authority to inspect vendor operations (via Right-to-Audit clauses) and independent verification of long-term operational control effectiveness (via SOC 2 Type II audit reports).

Step-by-Step Solution

1
Identify governance mechanisms for contractual access and verification
Establishing a contractual Right-to-Audit clause guarantees legal authorization to review and inspect the vendor's security posture.
Without explicit audit rights in contract agreements, service providers can deny enterprise security teams visibility into operational controls.
2
Determine appropriate third-party audit attestations for continuous control verification
Requiring SOC 2 Type II reports validates that controls were tested and effective over a sustained period of time.
SOC 2 Type II provides verifiable third-party assurance regarding security, availability, and confidentiality controls operating over time, unlike Type I which only checks point-in-time design.

Key Concept

Third-Party Governance and Vendor Oversight Controls
Rate this question