CRISC Information Technology and Security Practice Question
A risk practitioner is helping a mid-sized healthcare organization update its IT risk register after migrating patient scheduling to a SaaS platform. The vendor's SOC 2 Type II report shows no exceptions, but the contract omits breach notification timelines and data deletion commitments. Which action BEST addresses the residual risk?
⚠ Common exam trap
The trap here is assuming that a clean SOC 2 Type II report eliminates the need to address contractual gaps such as breach notification and data deletion terms.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amend the contract to include specific breach notification timelines, data deletion rights, and audit rights, then reassess the residual risk.
The vendor's SOC 2 Type II report gives assurance over controls, but it does not replace contractual protections. Missing breach notification timelines and data deletion commitments create legal, regulatory, and reputational risk that the organization must address. Amending the contract to include these terms, along with audit rights, directly mitigates the gap and allows the risk practitioner to reassess residual risk accurately.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the risk because the SOC 2 Type II report confirms the vendor's controls are operating effectively.
Why it's wrong here
A SOC 2 Type II report provides assurance over the vendor's controls at a point in time, but it does not cover contractual gaps such as breach notification timing or data deletion. Accepting the risk based solely on that report ignores the organization's own obligations to patients and regulators, leaving the residual risk unmanaged and potentially exposing the organization to notification delays and data retention violations.
- ✗
Transfer the risk by purchasing a cyber insurance policy that covers third-party data breaches.
Why it's wrong here
Cyber insurance can transfer some financial impact, but it does not compel the vendor to notify the organization promptly, nor does it ensure patient data is deleted at contract termination. The underlying contractual gaps remain, and insurance may exclude regulatory fines or require the organization to demonstrate due diligence. This leaves the residual risk largely unaddressed.
- ✓
Amend the contract to include specific breach notification timelines, data deletion rights, and audit rights, then reassess the residual risk.
Why this is correct
The SOC 2 report addresses the vendor's internal controls, but the missing contractual terms represent unmitigated legal and compliance risk. Amending the contract to add breach notification timelines, data deletion commitments, and audit rights directly addresses those gaps. Reassessing residual risk afterward ensures the risk register reflects the improved control environment and the organization's reduced exposure.
- ✗
Perform a penetration test against the SaaS platform to validate the vendor's security controls.
Why it's wrong here
Penetration testing can validate technical controls but typically requires vendor authorization and may not be permitted under the current contract. More importantly, it does not address the missing breach notification timelines or data deletion commitments, which are contractual and compliance gaps. The residual risk stems from legal and operational terms, not solely from technical vulnerabilities.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.