CompTIA Security+ (SY0-701)Security Program Management and OversightMedium

Before signing a contract with a new cloud storage vendor, a company requires the vendor to provide security certifications, financial stability documentation, and a completed security questionnaire. Which process is the company performing?

  1. AVendor due diligence
  2. BRight-to-audit clause negotiation
  3. CBusiness continuity planning
  4. DChange management review
Show answer & explanation

Correct answer: A. Vendor due diligence

Vendor due diligence is the pre-contract process of evaluating a third party's security posture, financial health, and compliance status before entering into an agreement.

Why the other options are wrong

  • B. A right-to-audit clause is a contractual term allowing future audits, not the pre-contract evaluation itself.
  • C. Business continuity planning focuses on maintaining operations during disruptions, not vendor vetting.
  • D. Change management review governs internal changes to systems, not vendor selection.

Vendor Due Diligence

The process of evaluating a third party's security, financial, and compliance posture before entering into a business relationship.

  • Performed before contract signing, unlike ongoing audits
  • Includes reviewing certifications (e.g., SOC 2), financials, and questionnaires
  • Reduces third-party and supply chain risk

Memory trick: Due diligence is 'doing your homework' before the deal.

More Security Program Management and Oversight questions