A financial services enterprise relies on a critical SaaS provider for processing customer transactions. To strengthen its third-party risk governance, the security team needs to establish continuous oversight to detect security posture changes between annual audit cycles without violating tenant boundaries. Which of the following technical and operational controls should the security team implement? (Select TWO.)
- Subscribe to third-party security rating services to dynamically monitor changes in the vendor's external attack surface and threat posture.Answer
- BDeploy inline intrusion prevention system (IPS) appliances directly within the provider's physical cloud data center network.
- Utilize a vendor risk management (VRM) platform to automate the ingestion and tracking of updated SOC 2 Type II attestation reports.Answer
- DSubstitute technical oversight by executing a Memorandum of Understanding (MOU) that guarantees zero operational security vulnerabilities.
- EMandate root-level administrative access to the vendor's multi-tenant virtualization hypervisors to run internal vulnerability scans.
Answer
The organization should subscribe to security rating services for external monitoring and utilize a vendor risk management platform to automate tracking of updated SOC 2 Type II attestations.
Effective third-party risk management requires ongoing oversight beyond annual point-in-time assessments. Subscribing to security rating services provides continuous external attack surface intelligence without disrupting operations. Concurrently, leveraging automated vendor risk management platforms guarantees prompt collection and analysis of updated third-party audit attestations, such as SOC 2 Type II reports.
Step-by-Step Solution
Key Concept
Continuous Third-Party Risk Monitoring and Vendor Oversight