Question

Difficulty: HardThird-Party Risk Management and Supply Chain Oversight

An enterprise organization is outsourcing its customer data analytics platform to a cloud service provider that will process sensitive financial records. To establish continuous risk oversight and maintain regulatory compliance throughout the contractual relationship, which of the following mechanisms should the organization require? (Select TWO.)

  1. Annual delivery of an independent SOC 2 Type II audit report assessing security controls over timeAnswer
  2. Inclusion of a mandatory security incident notification window within the contractual Service Level Agreement (SLA)Answer
  3. C
    Execution of a non-binding Memorandum of Understanding (MOU) to enforce endpoint detection agent installation on vendor hypervisors
  4. D
    Establishment of an Interconnection Security Agreement (ISA) to dictate physical tape destruction procedures
  5. E
    Mandatory deployment of honeypots within the vendor's code build pipeline to block malicious third-party updates

Answer

The organization should require annual independent SOC 2 Type II audit reports to verify operational control effectiveness over time, and mandate a formal security incident notification timeline within the Service Level Agreement (SLA).
Requiring annual independent SOC 2 Type II reports provides verifiable assurance that the cloud provider's security controls operate effectively over an extended period. Additionally, specifying a mandatory security incident notification timeframe within the SLA guarantees that the enterprise is alerted quickly during a security incident to fulfill legal and operational obligations.

Step-by-Step Solution

1
Identify third-party risk verification mechanisms for ongoing operational security oversight.
Recognize that a SOC 2 Type II report provides independent attestation of control effectiveness operating across an extended period.
Point-in-time assessments (like SOC 2 Type I or simple questionnaires) do not verify whether controls operated consistently over time.
2
Determine the necessary contractual controls to ensure prompt breach visibility and regulatory compliance.
Select a mandatory incident notification window specified in the Service Level Agreement (SLA).
Timely notification is required by data privacy regulations and enables the organization to initiate incident containment and notification protocols.
3
Evaluate and eliminate unsuitable governance and technical options.
Reject MOUs for hypervisor software enforcement, ISAs for physical tape disposal, and honeypots for inline build pipeline blocking due to control function misclassifications.
MOUs are non-binding, ISAs govern network connections, and honeypots serve threat detection rather than inline software blocking.

Key Concept

Third-party risk management relies on independent audit attestations (SOC 2 Type II) for ongoing control assurance and binding contractual terms (SLAs) for incident notification boundaries.
Rate this question