Study. uk . com
  1. Home
  2. All questions
  3. Question 720

CISM study material · question 720 of 1000

Which risk does NIST attach to engaging an incident response provider, and which deterrent does it name?

  1. Malicious insiders or compromise of the provider, deterred in part by non-disclosure agreements and contracting clauses
  2. Escalating cost, deterred by a fixed price contract
  3. Regulatory non-compliance, deterred by an audit clause
  4. Loss of the organisation's own detection capability, deterred by running parallel tooling in-house alongside whatever the provider operates
Show the answer

Answer: A. Malicious insiders or compromise of the provider, deterred in part by non-disclosure agreements and contracting clauses

SP 800-61r3 notes providers often have privileged access and access to sensitive data, so the risk of malicious insiders or the provider being compromised should be considered, with non-disclosure agreements and contracting clauses as options for deterring unauthorised disclosure.

Source: NIST SP 800-61 Rev. 3 (NIST) — Sec. 2.2 Roles and Responsibilities

Challenge yourself on this topic → Study as cards