An enterprise organization is outsourcing its customer data analytics platform to a cloud service provider that will process sensitive financial records. To establish continuous risk oversight and maintain regulatory compliance throughout the contractual relationship, which of the following mechanisms should the organization require? (Select TWO.)
- Annual delivery of an independent SOC 2 Type II audit report assessing security controls over timeCevap
- Inclusion of a mandatory security incident notification window within the contractual Service Level Agreement (SLA)Cevap
- CExecution of a non-binding Memorandum of Understanding (MOU) to enforce endpoint detection agent installation on vendor hypervisors
- DEstablishment of an Interconnection Security Agreement (ISA) to dictate physical tape destruction procedures
- EMandatory deployment of honeypots within the vendor's code build pipeline to block malicious third-party updates
Cevap
The organization should require annual independent SOC 2 Type II audit reports to verify operational control effectiveness over time, and mandate a formal security incident notification timeline within the Service Level Agreement (SLA).
Requiring annual independent SOC 2 Type II reports provides verifiable assurance that the cloud provider's security controls operate effectively over an extended period. Additionally, specifying a mandatory security incident notification timeframe within the SLA guarantees that the enterprise is alerted quickly during a security incident to fulfill legal and operational obligations.
Adım Adım Çözüm
Anahtar Kavram
Third-party risk management relies on independent audit attestations (SOC 2 Type II) for ongoing control assurance and binding contractual terms (SLAs) for incident notification boundaries.