- Home
- All questions
- Question 720
CISM study material · question 720 of 1000
Which risk does NIST attach to engaging an incident response provider, and which deterrent does it name?
Show the answer
Answer: A. Malicious insiders or compromise of the provider, deterred in part by non-disclosure agreements and contracting clauses
SP 800-61r3 notes providers often have privileged access and access to sensitive data, so the risk of malicious insiders or the provider being compromised should be considered, with non-disclosure agreements and contracting clauses as options for deterring unauthorised disclosure.
Source: NIST SP 800-61 Rev. 3 (NIST) — Sec. 2.2 Roles and Responsibilities