โ† All CCISO Flashcard Decks

Vendor Management Flashcards

7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Vendor Management flashcards as text
  1. A CISO is implementing a tiered vendor classification model. Which factor MOST heavily influences placing a vendor in the highest-risk tier?

    Answer: Volume and sensitivity of data accessed and criticality to business operations

    The highest-risk tier classification is driven primarily by the sensitivity of data the vendor accesses and how critical their service is to core business operations.

  2. Which of the following is the PRIMARY purpose of including a right-to-audit clause in a vendor contract?

    Answer: To allow the organization to verify vendor compliance with security requirements

    A right-to-audit clause grants the organization the contractual authority to assess whether the vendor is adhering to agreed security and compliance obligations.

  3. A fourth-party risk scenario occurs when:

    Answer: A vendor's own subcontractor causes a breach affecting your organization

    Fourth-party risk occurs when a vendor's supplier or subcontractor (a party not directly contracted by you) causes a security incident affecting your organization.

  4. During contract negotiations, a vendor refuses to accept liability for data breaches caused by their negligence. A CISO should PRIMARILY:

    Answer: Seek legal counsel and consider alternative vendors

    Accepting zero vendor liability for negligence-caused breaches transfers all risk to the organization; the CISO should involve legal counsel and evaluate alternatives.

  5. An organization's vendor sends a notice that they have suffered a ransomware attack and may not be able to deliver services. Which vendor management document MOST directly guides the organization's immediate response?

    Answer: Business continuity and incident response provisions in the vendor contract

    Contract provisions covering incident notification, business continuity, and escalation procedures directly govern the organization's response to a vendor security incident.

  6. Which metric is MOST useful for tracking the operational security performance of a vendor over time?

    Answer: Mean time to remediate vendor-reported security vulnerabilities

    Mean time to remediate (MTTR) security vulnerabilities is a concrete, measurable indicator of how seriously and quickly a vendor addresses security issues.

  7. A CISO learns that a key vendor has been acquired by a competitor. What is the FIRST action the CISO should take from a vendor risk management perspective?

    Answer: Re-assess the vendor's risk profile and review contract change-of-control provisions

    A change-of-control event warrants an immediate re-assessment of the vendor's risk posture and a review of any contractual provisions triggered by ownership changes.