โ† All CCISO Flashcard Decks

Vendor Management Flashcards

7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Vendor Management flashcards as text
  1. A CISO is selecting between two vendors: one holds ISO 27001 certification and the other provides a SOC 2 Type II report. Which statement BEST describes the difference?

    Answer: ISO 27001 certifies an ISMS against a standard; SOC 2 Type II reports on operational effectiveness of controls over a period

    ISO 27001 is a management system certification, while SOC 2 Type II is an attestation report covering the operational effectiveness of controls over a defined review period.

  2. An organization relies on a single vendor for 80% of its critical IT infrastructure. Which risk concept does this BEST illustrate?

    Answer: Vendor lock-in and single point of failure

    Over-reliance on a single vendor creates vendor lock-in and a single point of failure, significantly elevating operational and continuity risk.

  3. When a vendor handles cardholder data on behalf of an organization, which compliance framework DIRECTLY governs the vendor's security requirements?

    Answer: PCI DSS

    PCI DSS applies to any entity that stores, processes, or transmits cardholder data, including third-party vendors handling such data on behalf of merchants.

  4. A CISO wants to ensure vendors promptly notify the organization of security incidents. The contractual term that BEST enforces this requirement is:

    Answer: Incident notification clause with defined timeframes

    An incident notification clause with specific timeframes (e.g., within 72 hours) contractually obligates vendors to promptly report security incidents.

  5. Which approach BEST allows a CISO to assess a vendor's real-world security posture without performing a direct on-site audit?

    Answer: Requesting and reviewing a third-party penetration test report or SOC 2 Type II attestation

    Third-party audit reports such as SOC 2 Type II or penetration test summaries provide independent, evidence-based insights into vendor security effectiveness.

  6. In a vendor risk management program, which document defines the specific security controls a vendor must implement and maintain?

    Answer: Information security addendum or data processing agreement

    An information security addendum or data processing agreement details the specific security controls, obligations, and standards the vendor must maintain.

  7. A CISO discovers that a vendor's employees are using personal devices to access the organization's systems without authorization. This represents a violation of which policy type?

    Answer: Vendor acceptable use and access control policy

    Vendor acceptable use and access control policies govern how vendor personnel may access organizational systems and prohibit use of unauthorized personal devices.