CompTIA Security+ (SY0-701)Security Program Management and OversightMedium
A company wants contractual assurance that it can review a cloud service provider's security controls, logs, and processes at any time during the contract term to verify compliance. Which contractual element should be negotiated into the agreement?
- ARight-to-audit clause
- BService-level agreement
- CNon-disclosure agreement
- DMemorandum of understanding
Show answer & explanationAnswer & explanation
Correct answer: A. Right-to-audit clause
A right-to-audit clause grants the customer contractual authority to inspect or audit a vendor's security controls and processes during the contract period, which is a key third-party risk management tool.
Why the other options are wrong
- B. An SLA defines performance metrics like uptime, not audit rights.
- C. An NDA protects confidential information but does not grant audit rights.
- D. An MOU is a non-binding statement of intent between parties, not an enforceable audit mechanism.
Right-to-Audit Clause
A contractual provision that allows an organization to inspect and verify a third party's security controls and compliance during the business relationship.
- Key third-party risk management control
- Should be negotiated before contract signing
- Complements SLAs and vendor due diligence
Memory trick: Trust but Verify—Right to Audit Lets You Check