An organization has officially terminated its contract with a third-party software development vendor. To minimize third-party security risk immediately following the end of the contractual relationship, which of the following operational tasks should the security administrator complete first?
- Revoke all vendor user accounts, API keys, and remote access credentialsAnswer
- BRequest an updated SOC 2 Type II audit report from the vendor
- CDraft a new Memorandum of Understanding to govern future engagements
- DInitiate an external vulnerability scan against the vendor's public infrastructure
Answer
Revoke all vendor user accounts, API keys, and remote access credentials
When ending a contract with a third party, prompt revocation of all user accounts, federated identities, API tokens, and remote access permissions is the most critical first step. This ensures former vendor employees cannot retain access to sensitive corporate resources or data.
Step-by-Step Solution
Key Concept
Third-Party Offboarding and Access Lifecycle Management