CCISO Vendor Management 3 — Questions and Answers
Question 1: A CISO is implementing a tiered vendor classification model. Which factor MOST heavily influences placing a vendor in the highest-risk tier?
- Geographic location of vendor headquarters
- Volume and sensitivity of data accessed and criticality to business operations (Correct answer)
- Number of years the vendor has been in business
- Size of the vendor's annual revenue
Correct answer: Volume and sensitivity of data accessed and criticality to business operations
The highest-risk tier classification is driven primarily by the sensitivity of data the vendor accesses and how critical their service is to core business operations.
Question 2: Which of the following is the PRIMARY purpose of including a right-to-audit clause in a vendor contract?
- To enable the organization to renegotiate pricing at any time
- To allow the organization to verify vendor compliance with security requirements (Correct answer)
- To give the organization authority over vendor hiring decisions
- To restrict the vendor from working with competitors
Correct answer: To allow the organization to verify vendor compliance with security requirements
A right-to-audit clause grants the organization the contractual authority to assess whether the vendor is adhering to agreed security and compliance obligations.
Question 3: A fourth-party risk scenario occurs when:
- A vendor fails to meet SLA targets
- A vendor's own subcontractor causes a breach affecting your organization (Correct answer)
- An organization directly suffers a cyberattack
- A regulatory body audits the organization's vendor list
Correct answer: A vendor's own subcontractor causes a breach affecting your organization
Fourth-party risk occurs when a vendor's supplier or subcontractor (a party not directly contracted by you) causes a security incident affecting your organization.
Question 4: During contract negotiations, a vendor refuses to accept liability for data breaches caused by their negligence. A CISO should PRIMARILY:
- Accept the terms to accelerate procurement
- Seek legal counsel and consider alternative vendors (Correct answer)
- Remove the data security requirements from the contract
- Negotiate a lower service price to offset the risk
Correct answer: Seek legal counsel and consider alternative vendors
Accepting zero vendor liability for negligence-caused breaches transfers all risk to the organization; the CISO should involve legal counsel and evaluate alternatives.
Question 5: An organization's vendor sends a notice that they have suffered a ransomware attack and may not be able to deliver services. Which vendor management document MOST directly guides the organization's immediate response?
- Vendor performance scorecard
- Business continuity and incident response provisions in the vendor contract (Correct answer)
- Vendor onboarding checklist
- Vendor marketing agreement
Correct answer: Business continuity and incident response provisions in the vendor contract
Contract provisions covering incident notification, business continuity, and escalation procedures directly govern the organization's response to a vendor security incident.
Question 6: Which metric is MOST useful for tracking the operational security performance of a vendor over time?
- Vendor employee headcount growth
- Mean time to remediate vendor-reported security vulnerabilities (Correct answer)
- Number of vendor product releases per year
- Vendor's geographic expansion
Correct answer: Mean time to remediate vendor-reported security vulnerabilities
Mean time to remediate (MTTR) security vulnerabilities is a concrete, measurable indicator of how seriously and quickly a vendor addresses security issues.
Question 7: A CISO learns that a key vendor has been acquired by a competitor. What is the FIRST action the CISO should take from a vendor risk management perspective?
- Immediately terminate the vendor contract
- Re-assess the vendor's risk profile and review contract change-of-control provisions (Correct answer)
- Ignore the acquisition until the contract renewal date
- Transfer all vendor-held data to internal systems immediately
Correct answer: Re-assess the vendor's risk profile and review contract change-of-control provisions
A change-of-control event warrants an immediate re-assessment of the vendor's risk posture and a review of any contractual provisions triggered by ownership changes.
A CISO is implementing a tiered vendor classification model.
Which factor MOST heavily influences placing a vendor in the highest-risk tier?