Soru

Zorluk: OrtaThird-Party Risk Management and Supply Chain Oversight

A financial services enterprise relies on a critical SaaS provider for processing customer transactions. To strengthen its third-party risk governance, the security team needs to establish continuous oversight to detect security posture changes between annual audit cycles without violating tenant boundaries. Which of the following technical and operational controls should the security team implement? (Select TWO.)

  1. Subscribe to third-party security rating services to dynamically monitor changes in the vendor's external attack surface and threat posture.Cevap
  2. B
    Deploy inline intrusion prevention system (IPS) appliances directly within the provider's physical cloud data center network.
  3. Utilize a vendor risk management (VRM) platform to automate the ingestion and tracking of updated SOC 2 Type II attestation reports.Cevap
  4. D
    Substitute technical oversight by executing a Memorandum of Understanding (MOU) that guarantees zero operational security vulnerabilities.
  5. E
    Mandate root-level administrative access to the vendor's multi-tenant virtualization hypervisors to run internal vulnerability scans.

Cevap

The organization should subscribe to security rating services for external monitoring and utilize a vendor risk management platform to automate tracking of updated SOC 2 Type II attestations.
Effective third-party risk management requires ongoing oversight beyond annual point-in-time assessments. Subscribing to security rating services provides continuous external attack surface intelligence without disrupting operations. Concurrently, leveraging automated vendor risk management platforms guarantees prompt collection and analysis of updated third-party audit attestations, such as SOC 2 Type II reports.

Adım Adım Çözüm

1
Identify non-intrusive continuous monitoring techniques suitable for third-party oversight.
Selected external security rating services (SRS) which continuously evaluate public posture (patching, DNS hygiene, exposed assets) without penetrating vendor systems.
Security rating services allow ongoing risk visibility between annual formal security reviews.
2
Evaluate continuous artifact ingestion mechanisms.
Selected automated vendor risk management (VRM) portal tracking for SOC 2 Type II reports.
SOC 2 Type II reports audit operational effectiveness over a historical period; automated VRM ingestion ensures newly published audit reports are reviewed promptly.
3
Filter out ineffective, overly intrusive, or boundary-violating options.
Eliminated physical IPS deployment, hypervisor root access demands, and replacing monitoring with an MOU.
Physical deployments and hypervisor credentials violate cloud boundaries, while MOUs are non-binding administrative documents.

Anahtar Kavram

Continuous Third-Party Risk Monitoring and Vendor Oversight
Bu soruyu puanla