Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementMedium

A financial services company is evaluating a new third-party cloud provider to host its critical customer data. Before signing the contract, the company requires the provider to undergo a SOC 2 Type II audit and maintain specific data encryption standards. What aspect of risk management is the financial services company primarily addressing by imposing these requirements?

  1. ADefining the risk appetite
  2. BCalculating Annualized Loss Expectancy (ALE)
  3. CEstablishing a risk register
  4. DPerforming due diligence
Show answer & explanation

Correct answer: D. Performing due diligence

By requiring a SOC 2 Type II audit and specific encryption standards from a third-party vendor, the financial services company is conducting due diligence. This involves investigating and verifying the provider's security posture before committing to a contract to understand and manage associated risks.

Why the other options are wrong

  • A. Defining risk appetite is about the level of risk the organization is willing to accept.
  • B. ALE is a quantitative risk assessment metric, not directly related to setting vendor requirements.
  • C. A risk register is a document listing identified risks.

Due Diligence

The process of conducting a thorough investigation and review of a potential business partner, system, or process to identify and assess associated risks before making a decision or entering into an agreement.

  • Proactive risk assessment.
  • Involves thorough investigation.
  • Crucial for third-party relationships.

Memory trick: Vendors require Vigilant Due Diligence to Avoid Risk.

More Risk Management questions