CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium

An organization relies heavily on a third-party vendor for its critical cloud infrastructure. The risk practitioner is conducting a review of the vendor's disaster recovery capabilities. The vendor's Service Level Agreement (SLA) specifies a Recovery Point Objective (RPO) of 4 hours and a Recovery Time Objective (RTO) of 8 hours. The organization's internal business continuity plan requires an RPO of 2 hours and an RTO of 4 hours for this critical service. What is the MOST appropriate action for the CRISC practitioner to recommend?

  1. ANegotiate with the vendor to meet the organization's internal RPO/RTO requirements.
  2. BImplement additional internal controls to compensate for the vendor's RPO/RTO.
  3. CAccept the vendor's RPO/RTO as it is a common industry standard.
  4. DFind an alternative vendor that can meet the organization's RPO/RTO requirements immediately.
Show answer & explanation

Correct answer: A. Negotiate with the vendor to meet the organization's internal RPO/RTO requirements.

The vendor's capabilities do not meet the organization's critical requirements, indicating a gap. The most direct and often feasible first step is to negotiate with the current vendor to align their services with the organization's needs.

Why the other options are wrong

  • B. Implementing additional internal controls might be a fallback, but it's often more complex and less efficient than directly addressing the core issue with the vendor if possible.
  • C. Accepting the vendor's RPO/RTO would leave the organization exposed to unacceptable risk, as it exceeds internal requirements.
  • D. Finding an alternative vendor immediately might be a drastic and costly step without first attempting to resolve the issue with the current provider.

Third-Party Risk Alignment

Ensuring that the risk management and control capabilities of third-party vendors meet the organization's own risk tolerance and requirements, especially for critical services.

  • Critical services require thorough due diligence of vendor capabilities.
  • Vendor SLAs must align with organizational RTO/RPO and security standards.
  • Gaps in vendor capabilities against internal requirements must be addressed.
  • Negotiation is often the first step to resolve misalignments.

Memory trick: Align Vendor Requirements, Negotiate Gaps, or Seek New Engagement.

More Risk Response and Reporting questions