CCISO Vendor Management 2 — Questions and Answers
Question 1: A CISO is evaluating third-party vendors for cloud storage services. Which contractual clause BEST ensures the organization retains ownership of its data if the vendor relationship ends?
- Service Level Agreement (SLA)
- Data portability and return clause (Correct answer)
- Non-disclosure agreement (NDA)
- Indemnification clause
Correct answer: Data portability and return clause
A data portability and return clause contractually obligates the vendor to return or delete organizational data upon contract termination, ensuring data sovereignty.
Question 2: During a vendor risk assessment, the security team discovers a critical supplier uses the same IT infrastructure for multiple clients with no logical separation. This BEST represents which type of risk?
- Concentration risk (Correct answer)
- Regulatory risk
- Reputational risk
- Operational risk
Correct answer: Concentration risk
Concentration risk arises when a vendor's shared infrastructure creates potential exposure where a breach affecting one client could impact others.
Question 3: Which vendor management practice BEST helps a CISO ensure that security controls implemented by a vendor remain effective over time?
- One-time security questionnaire at onboarding
- Continuous monitoring and periodic re-assessment (Correct answer)
- Relying solely on vendor-provided audit reports
- Reviewing vendor marketing certifications annually
Correct answer: Continuous monitoring and periodic re-assessment
Continuous monitoring and periodic re-assessments ensure vendor security posture does not degrade after initial onboarding approval.
Question 4: An organization shares sensitive PII with a vendor for data analytics. Under GDPR, the vendor processing this data on behalf of the organization is classified as:
- Data controller
- Data processor (Correct answer)
- Data subject
- Data custodian
Correct answer: Data processor
Under GDPR, an entity that processes personal data on behalf of the controller (the organization) is classified as a data processor.
Question 5: A CISO wants to reduce the impact of a critical vendor going bankrupt. Which strategy is MOST effective for ensuring business continuity?
- Negotiate lower contract pricing
- Develop an alternative vendor or escrow arrangement (Correct answer)
- Require the vendor to purchase insurance
- Increase the frequency of invoice reviews
Correct answer: Develop an alternative vendor or escrow arrangement
Maintaining an alternative vendor or software escrow arrangement ensures continuity of critical services if the primary vendor ceases operations.
Question 6: When performing due diligence on a new vendor's financial stability, which document is MOST relevant to assess the vendor's ability to sustain operations?
- Vendor's marketing brochure
- Audited financial statements (Correct answer)
- Vendor's customer testimonials
- Product roadmap documentation
Correct answer: Audited financial statements
Audited financial statements provide an objective, verified view of a vendor's financial health and operational sustainability.
Question 7: A vendor management policy requires that all vendors with access to sensitive systems undergo background checks on their employees. This control PRIMARILY addresses which risk?
- Regulatory non-compliance
- Insider threat from vendor personnel (Correct answer)
- Data residency violations
- License compliance issues
Correct answer: Insider threat from vendor personnel
Background checks on vendor employees mitigate insider threat risk by vetting individuals who may have access to sensitive organizational systems.
A CISO is evaluating third-party vendors for cloud storage services.
Which contractual clause BEST ensures the organization retains ownership of its data if the vendor relationship ends?