ISC2 Certified in Cybersecurity (CC)Security OperationsMedium

An organization relies heavily on a third-party cloud provider for its critical data storage and processing. Before signing the contract, the organization's security team conducts a thorough review of the cloud provider's security certifications, incident response capabilities, and data protection policies. They also require the provider to agree to regular security audits. This due diligence is a critical part of which security operations domain?

  1. AThird-party risk management
  2. BEnvironmental controls
  3. CAsset management
  4. DConfiguration management
Show answer & explanation

Correct answer: A. Third-party risk management

The scenario explicitly describes assessing the security posture and contractual obligations of an external entity (cloud provider) that handles sensitive organizational data. This falls directly under third-party risk management.

Why the other options are wrong

  • B. Environmental controls deal with physical conditions, not external vendor security.
  • C. Asset management tracks internal assets, not the risk posed by external providers.
  • D. Configuration management focuses on internal system settings, not external vendor relationships.

Third-Party Risk Management

The process of identifying, assessing, and mitigating risks associated with external vendors, suppliers, and partners who have access to an organization's systems, data, or processes.

  • Crucial for supply chain security
  • Involves due diligence, contract review, and ongoing monitoring
  • Aims to protect organizational assets accessed by third parties

Memory trick: Trusting others requires careful checks.

More Security Operations questions