QuestionQ370

Risk Optimization

A business unit intends to replace an existing legacy IT solution with a hosted Software as a Service (SaaS) solution. However, business management is concerned that data held by the provider could be at risk. Which of the following is the MOST effective way to reduce the risk associated with the SaaS solution?

  • A Include risk-related requirements in the SaaS contract.
  • B Create key risk indicators for the SaaS solution.
  • C Redefine the risk appetite and risk tolerance.
  • D Research the technology and identify potential security threats.
Explanation

Risk-related requirements in the SaaS contract make the provider accountable for defined data-security, privacy, availability, incident-notification, audit, and remediation obligations. This directly mitigates third-party data risk by establishing enforceable controls and remedies for the hosted service. NIST guidance identifies cloud service agreements as a key mechanism for addressing cloud-computing risks and security considerations.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!