FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management
A bank's cloud vendor contract states that the vendor is responsible for the security of the cloud infrastructure, while the bank configures access controls and data encryption for its own workloads. After a breach caused by a publicly exposed storage bucket the bank configured itself, the bank's board asks who bears responsibility. What is the most appropriate conclusion under the shared responsibility model?
The bank remains accountable. In a shared responsibility model the provider secures the infrastructure, but the customer is responsible for configuring access, encryption and its data. The exposed storage bucket was the bank's own misconfiguration, and outsourcing does not transfer ultimate accountability.
- AThe bank remains accountable, because misconfiguration of its own workloads falls on the customer sideCorrect
- BThe cloud vendor is fully accountable, because the data resided on its infrastructure
- CResponsibility is transferred to the vendor once the contract is signed
- DAccountability is shared equally regardless of who made the configuration
Explanation
Under the shared responsibility model the provider secures the underlying infrastructure, while the customer secures what it configures and its data. The exposed bucket was a customer configuration error. Outsourcing never removes the bank's ultimate accountability for its data and risk.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.
More Case Study: Third-party Risk Management questions
- A bank assesses an outsourced critical service. The primary vendor has a 2% annual probability of a disruption exceeding the bank's impact t…
- A bank assesses 10 critical applications. Cloud Provider A hosts 4, Provider B hosts 3, Provider C hosts 2 and Provider D hosts 1. Using the…
- A bank uses a scorecard to rank vendors by residual risk. Inherent risk is scored 1-5 and control effectiveness reduces it by a factor: resi…
- A mid-sized asset manager is deciding whether to outsource its fund accounting function. Which of the following is the most typical strategi…
- A bank monitors a critical vendor using key risk indicators. Which set would best provide forward-looking early warning of deteriorating ven…
- A bank sets an impact tolerance of 8 hours maximum disruption for a critical payments service. A scenario test of a vendor failure shows: ve…