ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Hard
A financial institution is integrating a new cloud-based customer relationship management (CRM) system that will store sensitive customer data. They are concerned about ensuring the confidentiality and integrity of identity data managed by the third-party cloud provider. Which of the following is the MOST effective contractual and technical control combination to mitigate these risks?
- AEstablishing a robust Service Level Agreement (SLA) with data protection clauses and implementing data encryption at rest and in transit.
- BMandating regular external penetration tests and using client-side encryption for all data.
- CRequiring the vendor to sign a Non-Disclosure Agreement (NDA) and implementing a strong password policy.
- DInsisting on physical access controls to the vendor's data center and relying solely on the vendor's default security configurations.
Show answer & explanationAnswer & explanation
Correct answer: A. Establishing a robust Service Level Agreement (SLA) with data protection clauses and implementing data encryption at rest and in transit.
A robust SLA with specific data protection clauses legally binds the vendor to confidentiality and integrity standards. Technically, implementing data encryption at rest (for stored data) and in transit (for data movement) directly protects confidentiality and integrity against unauthorized access and tampering, providing a strong combination of controls.
Why the other options are wrong
- B. Regular penetration tests are good, but client-side encryption for ALL data is often impractical and can break application functionality; it's not always the MOST effective and comprehensive solution.
- C. An NDA is a basic contractual control, but a strong password policy alone for the institution's users doesn't address the vendor's handling of data confidentiality and integrity.
- D. Insisting on physical access controls is important but difficult to enforce for cloud providers, and relying solely on default vendor security is a significant risk, not a mitigation.
Third-Party Identity Services Security
Securing identity data and access when using external cloud or managed identity providers, requiring both contractual and technical controls.
- Requires due diligence on vendor security practices.
- Contractual agreements (SLAs) are critical.
- Technical controls like encryption are essential.
Memory trick: Contractual SLAs and Encryption Secure Cloud Data