While contract negotiation (option A) is an important aspect of engaging with a third-party security service, it is not the BEST explanation when determining whether to provide remote network access to that service. The question specifically asks for the BEST explanation, and in this context, the primary consideration should be the business need (option C).
Contract negotiation typically occurs after assessing the business need and deciding to proceed with engaging a third-party security service. During contract negotiation, the terms and conditions of the engagement are discussed and agreed upon, including aspects such as service levels, pricing, confidentiality, liability, and legal obligations.
Therefore, while contract negotiation is relevant, option C (business need) is the BEST explanation for deciding whether to provide remote network access to a third-party security service.
Providing remote network access to a third-party security service is a decision that should be made based on the specific business needs and the risks involved. It is important to evaluate the requirements for the service and whether it is critical for the business operations.
The best explanation when determining whether to provide remote network access to a third-party security service is Business Need. Remote network access should only be provided if there is a specific business need that cannot be met without the service. It is important to consider the security implications of providing remote access and to ensure that the third-party service adheres to the organization's security policies and practices.
I will select A.
Third-Party Security Services Provider (TPSSP)
The security roles and responsibilities of TPSSPs for:
- Identity and access management
- Cloud Workload Protection Platform
- Network Security
- Data & Storage Security
- Assessment
- Security Analytics as a Service
- Application Security
- Security Support Services
Normally we need to negotiate roles & responsibilities of TPSSP. Service Level Agreement(SLAs) and types of support (On-site or Remote Access) have to be clarified.
Reference : https://www.lexology.com/library/detail.aspx?g=3ed47921-2cfa-4d1b-8615-ad468a1cbc81
Answer is A
For e.g , When working with a 3rd party on an internal project , if they need VPN access to meet the business need , the access is granted a part of contract negotiation .
Disagree. Cyber policy dictates business needs for access. Not any element of the business contract. The 3rd party has NO RIGHTS to be on the network.
upvoted 2 times
...
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
stickerbush1970
Highly Voted 2 years, 2 months agojackdryan
1 year, 6 months agoNithstar
Most Recent 4 months agoMoose01
1 year, 1 month agoMD806
1 year, 2 months agoBach1968
1 year, 4 months agoJenkins3mol
6 months, 4 weeks agoKelvinYau
1 year, 5 months agos_n_
1 year, 9 months agoJoadeika
1 year, 10 months agodumdada
1 year, 5 months agocccispman
1 year, 11 months agosomkiatr
1 year, 11 months agoKayChan
1 year, 11 months agorootic
2 years agoDButtare
2 years, 2 months agostickerbush1970
2 years, 2 months agokptest12
2 years, 2 months agoJoey456
2 years, 1 month ago