A bank discovers that a critical payment processor subcontracted data handling to a fourth-party provider without prior notification. What is the MOST appropriate immediate response?
-
A
Terminate the primary vendor contract immediately
-
B
Invoke the contract clause requiring prior approval for subcontracting and conduct a risk assessment of the fourth party
-
C
Report the incident to regulators before investigating further
-
D
Accept the arrangement if the fourth party has an ISO 27001 certification