Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementMedium
A financial services company is evaluating a new third-party cloud provider to host its critical customer data. Before signing the contract, the company requires the provider to undergo a SOC 2 Type II audit and maintain specific data encryption standards. What aspect of risk management is the financial services company primarily addressing by imposing these requirements?
- ADefining the risk appetite
- BCalculating Annualized Loss Expectancy (ALE)
- CEstablishing a risk register
- DPerforming due diligence
Show answer & explanationAnswer & explanation
Correct answer: D. Performing due diligence
By requiring a SOC 2 Type II audit and specific encryption standards from a third-party vendor, the financial services company is conducting due diligence. This involves investigating and verifying the provider's security posture before committing to a contract to understand and manage associated risks.
Why the other options are wrong
- A. Defining risk appetite is about the level of risk the organization is willing to accept.
- B. ALE is a quantitative risk assessment metric, not directly related to setting vendor requirements.
- C. A risk register is a document listing identified risks.
Due Diligence
The process of conducting a thorough investigation and review of a potential business partner, system, or process to identify and assess associated risks before making a decision or entering into an agreement.
- Proactive risk assessment.
- Involves thorough investigation.
- Crucial for third-party relationships.
Memory trick: Vendors require Vigilant Due Diligence to Avoid Risk.