A healthcare organization is preparing to contract with a third-party Cloud Service Provider (CSP) to host electronic protected health information. During the vendor onboarding security review, the organization must establish ongoing oversight and technical verification of the provider's security controls across the contract lifecycle. Which of the following strategies should the organization enforce to validate third-party security posture and maintain supply chain governance? (Select TWO.)
- Require the vendor to provide annual SOC 2 Type II reports to evaluate the operational effectiveness of security controls over time.Answer
- BRely on annual SOC 2 Type I reports to verify that security controls continuously prevent security incidents throughout the contract term.
- Incorporate contractual right-to-audit clauses and continuous monitoring requirements into the Service Level Agreement (SLA).Answer
- DDeploy inline network firewalls inside the third-party provider's datacenter to mitigate host application vulnerabilities.
- EExecute a non-binding Memorandum of Understanding (MOU) to establish legally enforceable financial liability for data breaches.
Answer
The organization must require annual SOC 2 Type II audit reports and incorporate contractual right-to-audit clauses along with continuous monitoring requirements.
Effective supply chain risk management relies on independent attestation and enforceable contractual oversight. SOC 2 Type II reports evaluate control operating effectiveness over a extended period, verifying that security practices are functioning consistently over time. Additionally, contractual right-to-audit provisions combined with continuous monitoring give the organization the legal authority and capability to inspect third-party controls and track security posture changes over the agreement lifetime.
Step-by-Step Solution
Key Concept
Third-Party Oversight, SOC Reports, and Right-to-Audit Provisions