CompTIA Security+ (SY0-701)Security Program Management and OversightMedium

A company wants contractual assurance that it can review a cloud service provider's security controls, logs, and processes at any time during the contract term to verify compliance. Which contractual element should be negotiated into the agreement?

  1. ARight-to-audit clause
  2. BService-level agreement
  3. CNon-disclosure agreement
  4. DMemorandum of understanding
Show answer & explanation

Correct answer: A. Right-to-audit clause

A right-to-audit clause grants the customer contractual authority to inspect or audit a vendor's security controls and processes during the contract period, which is a key third-party risk management tool.

Why the other options are wrong

  • B. An SLA defines performance metrics like uptime, not audit rights.
  • C. An NDA protects confidential information but does not grant audit rights.
  • D. An MOU is a non-binding statement of intent between parties, not an enforceable audit mechanism.

Right-to-Audit Clause

A contractual provision that allows an organization to inspect and verify a third party's security controls and compliance during the business relationship.

  • Key third-party risk management control
  • Should be negotiated before contract signing
  • Complements SLAs and vendor due diligence

Memory trick: Trust but Verify—Right to Audit Lets You Check

More Security Program Management and Oversight questions