SY0-701 Question 439
Single answer5.3 Explain the processes associated with third-party risk assessment and management.A healthcare company is evaluating a cloud-based billing vendor that will store and process protected health information (PHI). The security manager has been asked to reduce third-party risk before the contract is signed. Which of the following actions is the BEST way to verify the vendor's security posture as part of the due diligence process?
- A
Require the vendor to complete a security questionnaire and provide recent independent audit evidence such as a SOC 2 report or ISO 27001 certification details
- B
Rely on the vendor's marketing materials that state the environment is encrypted and compliant with healthcare regulations
- C
Delay all security review activities until after onboarding so production logs can be evaluated
- D
Accept the vendor based on the fact that several competitors already use the same service
Show answer and explanation
Correct answer: A
Explanation
The best answer is to perform structured due diligence using a security questionnaire and independent assurance evidence before the relationship begins. In third-party risk assessment and management, organizations typically evaluate vendors based on inherent risk, the type of data involved, service criticality, compliance impact, and available control evidence. For a healthcare environment processing PHI, reviewing external audit artifacts and control documentation is a strong method for validating claims and supporting risk-based onboarding decisions. This aligns with common third-party risk management practices reflected in NIST Cybersecurity Supply Chain Risk Management guidance (NIST SP 800-161), NIST SP 800-171/800-53 control assessment concepts, and industry use of independent attestation reports such as SOC 2. Contractual protections, business associate agreements where applicable, and ongoing monitoring are also important, but they do not replace initial due diligence.
- A. Correct.
Correct. Third-party risk assessment starts with due diligence before onboarding. A security questionnaire helps identify how the vendor handles controls such as access management, incident response, encryption, and data retention. Independent attestations or certifications, such as a SOC 2 report or ISO 27001 certification scope and audit details, provide objective evidence that controls were assessed by an external party. For a vendor handling PHI, this is a practical and standard way to validate security posture before signing a contract.
- B. Incorrect.
Incorrect. Marketing claims are not sufficient evidence for third-party risk management. Vendors often describe security features in broad terms, but those statements do not confirm control effectiveness, scope, or audit results. A risk assessor should seek documented and independently validated evidence rather than promotional content.
- C. Incorrect.
Incorrect. Security review should occur before onboarding whenever possible, especially when sensitive data such as PHI is involved. Waiting until after onboarding increases exposure and may allow the organization to enter into a risky relationship without understanding contractual, technical, or compliance gaps. Ongoing monitoring is important, but it does not replace pre-contract due diligence.
- D. Incorrect.
Incorrect. Industry adoption or customer popularity does not prove that the vendor meets this organization's security, compliance, or contractual requirements. This is a common misconception in vendor management. Each organization must assess vendors based on its own risk tolerance, data sensitivity, regulatory obligations, and required controls.