QuestionQ466

Risk Optimization

After deploying an enterprise IT software solution that stores sensitive data, it was found that the application's role-based access control did not function as specified. Which of the following is the BEST way to prevent this from happening again in the future?

  • A Ensure procurement processes require the identification of alternate vendors to ensure business continuity.
  • B Ensure the evaluation process requires independent assessment of solutions prior to implementation.
  • C Ensure supplier contracts include a provision for the right to audit on an annual basis.
  • D Ensure supplier contracts include penalties if solutions do not meet functional requirements.
Explanation

An independent pre-implementation assessment can validate that role-based access control operates as required before the solution is deployed. Security-control assessment procedures are intended to verify that controls are implemented and achieve their stated objectives; contractual audit rights or penalties do not provide that preventive validation.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!