Skip to content

FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management

A bank's cloud vendor contract states that the vendor is responsible for the security of the cloud infrastructure, while the bank configures access controls and data encryption for its own workloads. After a breach caused by a publicly exposed storage bucket the bank configured itself, the bank's board asks who bears responsibility. What is the most appropriate conclusion under the shared responsibility model?

The bank remains accountable. In a shared responsibility model the provider secures the infrastructure, but the customer is responsible for configuring access, encryption and its data. The exposed storage bucket was the bank's own misconfiguration, and outsourcing does not transfer ultimate accountability.

  1. AThe bank remains accountable, because misconfiguration of its own workloads falls on the customer sideCorrect
  2. BThe cloud vendor is fully accountable, because the data resided on its infrastructure
  3. CResponsibility is transferred to the vendor once the contract is signed
  4. DAccountability is shared equally regardless of who made the configuration

Explanation

Under the shared responsibility model the provider secures the underlying infrastructure, while the customer secures what it configures and its data. The exposed bucket was a customer configuration error. Outsourcing never removes the bank's ultimate accountability for its data and risk.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.

More Case Study: Third-party Risk Management questions