โ† All CCISO Flashcard Decks

Vendor Management Flashcards

7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Vendor Management flashcards as text
  1. A CISO is evaluating third-party vendors for cloud storage services. Which contractual clause BEST ensures the organization retains ownership of its data if the vendor relationship ends?

    Answer: Data portability and return clause

    A data portability and return clause contractually obligates the vendor to return or delete organizational data upon contract termination, ensuring data sovereignty.

  2. During a vendor risk assessment, the security team discovers a critical supplier uses the same IT infrastructure for multiple clients with no logical separation. This BEST represents which type of risk?

    Answer: Concentration risk

    Concentration risk arises when a vendor's shared infrastructure creates potential exposure where a breach affecting one client could impact others.

  3. Which vendor management practice BEST helps a CISO ensure that security controls implemented by a vendor remain effective over time?

    Answer: Continuous monitoring and periodic re-assessment

    Continuous monitoring and periodic re-assessments ensure vendor security posture does not degrade after initial onboarding approval.

  4. An organization shares sensitive PII with a vendor for data analytics. Under GDPR, the vendor processing this data on behalf of the organization is classified as:

    Answer: Data processor

    Under GDPR, an entity that processes personal data on behalf of the controller (the organization) is classified as a data processor.

  5. A CISO wants to reduce the impact of a critical vendor going bankrupt. Which strategy is MOST effective for ensuring business continuity?

    Answer: Develop an alternative vendor or escrow arrangement

    Maintaining an alternative vendor or software escrow arrangement ensures continuity of critical services if the primary vendor ceases operations.

  6. When performing due diligence on a new vendor's financial stability, which document is MOST relevant to assess the vendor's ability to sustain operations?

    Answer: Audited financial statements

    Audited financial statements provide an objective, verified view of a vendor's financial health and operational sustainability.

  7. A vendor management policy requires that all vendors with access to sensitive systems undergo background checks on their employees. This control PRIMARILY addresses which risk?

    Answer: Insider threat from vendor personnel

    Background checks on vendor employees mitigate insider threat risk by vetting individuals who may have access to sensitive organizational systems.