ISC2 Certified in Cybersecurity (CC)Security OperationsMedium
An organization relies heavily on a third-party cloud provider for its critical data storage and processing. Before signing the contract, the organization's security team conducts a thorough review of the cloud provider's security certifications, incident response capabilities, and data protection policies. They also require the provider to agree to regular security audits. This due diligence is a critical part of which security operations domain?
- AThird-party risk management
- BEnvironmental controls
- CAsset management
- DConfiguration management
Show answer & explanationAnswer & explanation
Correct answer: A. Third-party risk management
The scenario explicitly describes assessing the security posture and contractual obligations of an external entity (cloud provider) that handles sensitive organizational data. This falls directly under third-party risk management.
Why the other options are wrong
- B. Environmental controls deal with physical conditions, not external vendor security.
- C. Asset management tracks internal assets, not the risk posed by external providers.
- D. Configuration management focuses on internal system settings, not external vendor relationships.
Third-Party Risk Management
The process of identifying, assessing, and mitigating risks associated with external vendors, suppliers, and partners who have access to an organization's systems, data, or processes.
- Crucial for supply chain security
- Involves due diligence, contract review, and ongoing monitoring
- Aims to protect organizational assets accessed by third parties
Memory trick: Trusting others requires careful checks.