Cisco CCNP Security Core (SCOR) 350-701Security ConceptsHard
A multinational corporation is considering outsourcing its entire IT infrastructure to a cloud service provider (CSP). Before finalizing the contract, their legal and security teams are meticulously reviewing the CSP's Service Level Agreements (SLAs), compliance certifications (e.g., ISO 27001, SOC 2), and data processing agreements to ensure they meet the company's stringent data protection requirements and regulatory obligations across all operating regions. What specific area of security governance is being addressed by this comprehensive due diligence?
- ASecurity awareness program oversight
- BThird-party risk management
- CInternal security audit planning
- DSecurity operations management
Show answer & explanationAnswer & explanation
Correct answer: B. Third-party risk management
The scenario describes a 'multinational corporation' engaging with a 'cloud service provider' and reviewing their security posture, SLAs, and compliance. This extensive process to manage the security risks introduced by a vendor is precisely 'third-party risk management', a critical function within security governance.
Why the other options are wrong
- A. Awareness programs focus on internal employees, not external vendors.
- C. Internal audits assess internal controls; this is evaluating an external entity.
- D. Security operations manage day-to-day security; this is about vendor selection.
Third-Party Risk Management (TPRM)
The process of identifying, assessing, and mitigating risks associated with outsourcing business functions or using services provided by external vendors, suppliers, or partners.
- Crucial for maintaining supply chain security and regulatory compliance.
- Involves due diligence, contract review, ongoing monitoring, and termination planning.
- Risks include data breaches, service disruptions, and compliance failures.
Memory trick: When you outsource, you outsource the work, not the risk.