Soru

Zorluk: ZorThird-Party Risk Management and Supply Chain Oversight

An enterprise financial institution relies on a custom, proprietary fraud detection application supplied by a niche third-party software vendor. During an annual supply chain risk assessment, the security team identifies a major operational risk: if the software vendor unexpectedly faces insolvency, goes out of business, or fails to maintain the application, the institution will lose the ability to update or fix critical bugs in the software. Which of the following risk mitigation provisions should the security team implement in the vendor agreement to directly resolve this continuity risk?

  1. A software escrow agreement requiring the vendor to deposit source code and build instructions with a neutral third party.Cevap
  2. B
    A service level agreement (SLA) establishing strict system uptime targets and financial remedies for unapproved downtime.
  3. C
    A business partner agreement (BPA) establishing shared financial liability and joint leadership oversight between both entities.
  4. D
    A non-disclosure agreement (NDA) containing strict confidentiality requirements and intellectual property protection terms.

Cevap

A software escrow agreement requiring the vendor to deposit source code and build instructions with a neutral third party.
A software escrow agreement directly mitigates third-party vendor bankruptcy and abandonment risk. Under this arrangement, the software vendor deposits the application source code, compile instructions, and documentation with an independent third-party escrow agent. If the vendor goes out of business or fails to meet contractual maintenance obligations, the escrow agent releases the code to the customer, enabling them to maintain and operate the software independently.

Adım Adım Çözüm

1
Analyze the specific supply chain risk described in the scenario.
The risk is operational disruption and loss of software maintenance capabilities due to potential vendor insolvency or business failure.
The organization depends on a custom proprietary application whose underlying source code is controlled exclusively by an external vendor.
2
Evaluate third-party contract types against the requirement to preserve source code availability.
A software escrow agreement places source code, build scripts, and documentation with a trusted neutral trustee to be released upon triggered events (e.g., bankruptcy or abandonment).
Escrow mechanisms preserve software maintenance rights for the buyer even if the original vendor goes out of business.
3
Differentiate software escrow from operational and confidentiality agreements.
SLAs, BPAs, and NDAs govern performance metrics, partnership terms, and secrecy respectively, but none provide source code release mechanisms upon vendor liquidation.
Standard legal agreements without escrow clauses leave the customer without legal or technical access to proprietary source code.

Anahtar Kavram

Software Escrow Agreements in Third-Party Risk Management
Bu soruyu puanla