Study. uk . com
  1. Home
  2. All questions
  3. Question 37

CompTIA Security+ study material · question 37 of 611

An organisation wants to impose security requirements on a SaaS provider. When does it have the most leverage to do so?

  1. After the first security incident
  2. Before the contract is signed
  3. When the service is fully embedded in operations
  4. At the annual renewal review
Show the answer

Answer: B. Before the contract is signed

Once the service is embedded, switching cost falls on the customer and the ability to demand changes drops sharply.

Source: NIST SP 800-161 Rev. 1 (NIST) — SP 800-161 Rev. 1 › Supplier Relationships

Challenge yourself on this topic → Study as cards