CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium
An organization relies heavily on a third-party vendor for its critical cloud infrastructure. The risk practitioner is conducting a review of the vendor's disaster recovery capabilities. The vendor's Service Level Agreement (SLA) specifies a Recovery Point Objective (RPO) of 4 hours and a Recovery Time Objective (RTO) of 8 hours. The organization's internal business continuity plan requires an RPO of 2 hours and an RTO of 4 hours for this critical service. What is the MOST appropriate action for the CRISC practitioner to recommend?
- ANegotiate with the vendor to meet the organization's internal RPO/RTO requirements.
- BImplement additional internal controls to compensate for the vendor's RPO/RTO.
- CAccept the vendor's RPO/RTO as it is a common industry standard.
- DFind an alternative vendor that can meet the organization's RPO/RTO requirements immediately.
Show answer & explanationAnswer & explanation
Correct answer: A. Negotiate with the vendor to meet the organization's internal RPO/RTO requirements.
The vendor's capabilities do not meet the organization's critical requirements, indicating a gap. The most direct and often feasible first step is to negotiate with the current vendor to align their services with the organization's needs.
Why the other options are wrong
- B. Implementing additional internal controls might be a fallback, but it's often more complex and less efficient than directly addressing the core issue with the vendor if possible.
- C. Accepting the vendor's RPO/RTO would leave the organization exposed to unacceptable risk, as it exceeds internal requirements.
- D. Finding an alternative vendor immediately might be a drastic and costly step without first attempting to resolve the issue with the current provider.
Third-Party Risk Alignment
Ensuring that the risk management and control capabilities of third-party vendors meet the organization's own risk tolerance and requirements, especially for critical services.
- Critical services require thorough due diligence of vendor capabilities.
- Vendor SLAs must align with organizational RTO/RPO and security standards.
- Gaps in vendor capabilities against internal requirements must be addressed.
- Negotiation is often the first step to resolve misalignments.
Memory trick: Align Vendor Requirements, Negotiate Gaps, or Seek New Engagement.