Question

Difficulty: MediumThird-Party Risk Management and Supply Chain Oversight

A healthcare organization is preparing to contract with a third-party Cloud Service Provider (CSP) to host electronic protected health information. During the vendor onboarding security review, the organization must establish ongoing oversight and technical verification of the provider's security controls across the contract lifecycle. Which of the following strategies should the organization enforce to validate third-party security posture and maintain supply chain governance? (Select TWO.)

  1. Require the vendor to provide annual SOC 2 Type II reports to evaluate the operational effectiveness of security controls over time.Answer
  2. B
    Rely on annual SOC 2 Type I reports to verify that security controls continuously prevent security incidents throughout the contract term.
  3. Incorporate contractual right-to-audit clauses and continuous monitoring requirements into the Service Level Agreement (SLA).Answer
  4. D
    Deploy inline network firewalls inside the third-party provider's datacenter to mitigate host application vulnerabilities.
  5. E
    Execute a non-binding Memorandum of Understanding (MOU) to establish legally enforceable financial liability for data breaches.

Answer

The organization must require annual SOC 2 Type II audit reports and incorporate contractual right-to-audit clauses along with continuous monitoring requirements.
Effective supply chain risk management relies on independent attestation and enforceable contractual oversight. SOC 2 Type II reports evaluate control operating effectiveness over a extended period, verifying that security practices are functioning consistently over time. Additionally, contractual right-to-audit provisions combined with continuous monitoring give the organization the legal authority and capability to inspect third-party controls and track security posture changes over the agreement lifetime.

Step-by-Step Solution

1
Analyze third-party risk verification requirements
Effective governance requires both independent attestation of control operating effectiveness over time and contractual rights to inspect or continuously monitor vendor risk posture.
Point-in-time attestations or non-binding agreements do not provide adequate governance for sensitive cloud environments.
2
Evaluate third-party audit report types
SOC 2 Type II reports review operational effectiveness over a testing window, whereas SOC 2 Type I reports only assess control suitability at a single timestamp.
Ongoing verification requires a Type II evaluation to confirm controls worked consistently over time.
3
Select contractual and oversight mechanisms
Including right-to-audit clauses ensures the organization maintains legal access to request security evidence, conduct assessments, or mandate metrics reporting within SLAs.
Contractual enforcement mechanisms ensure third parties remain accountable to enterprise security standards.

Key Concept

Third-Party Oversight, SOC Reports, and Right-to-Audit Provisions
Rate this question