An organization has officially terminated its contract with a third-party software development vendor. To minimize third-party security risk immediately following the end of the contractual relationship, which of the following operational tasks should the security administrator complete first?
- Revoke all vendor user accounts, API keys, and remote access credentialsCevap
- BRequest an updated SOC 2 Type II audit report from the vendor
- CDraft a new Memorandum of Understanding to govern future engagements
- DInitiate an external vulnerability scan against the vendor's public infrastructure
Cevap
Revoke all vendor user accounts, API keys, and remote access credentials
When ending a contract with a third party, prompt revocation of all user accounts, federated identities, API tokens, and remote access permissions is the most critical first step. This ensures former vendor employees cannot retain access to sensitive corporate resources or data.
Adım Adım Çözüm
Anahtar Kavram
Third-Party Offboarding and Access Lifecycle Management