CCISO Vendor Management 4 — Questions and Answers
Question 1: A CISO is selecting between two vendors: one holds ISO 27001 certification and the other provides a SOC 2 Type II report. Which statement BEST describes the difference?
- ISO 27001 is US-specific; SOC 2 is international
- ISO 27001 certifies an ISMS against a standard; SOC 2 Type II reports on operational effectiveness of controls over a period (Correct answer)
- SOC 2 is a certification; ISO 27001 is an audit report
- Both certifications are identical in scope and value
Correct answer: ISO 27001 certifies an ISMS against a standard; SOC 2 Type II reports on operational effectiveness of controls over a period
ISO 27001 is a management system certification, while SOC 2 Type II is an attestation report covering the operational effectiveness of controls over a defined review period.
Question 2: An organization relies on a single vendor for 80% of its critical IT infrastructure. Which risk concept does this BEST illustrate?
- Vendor lock-in and single point of failure (Correct answer)
- Economies of scale
- Regulatory concentration limits
- Supplier diversity compliance
Correct answer: Vendor lock-in and single point of failure
Over-reliance on a single vendor creates vendor lock-in and a single point of failure, significantly elevating operational and continuity risk.
Question 3: When a vendor handles cardholder data on behalf of an organization, which compliance framework DIRECTLY governs the vendor's security requirements?
- HIPAA
- PCI DSS (Correct answer)
- SOX
- FISMA
Correct answer: PCI DSS
PCI DSS applies to any entity that stores, processes, or transmits cardholder data, including third-party vendors handling such data on behalf of merchants.
Question 4: A CISO wants to ensure vendors promptly notify the organization of security incidents. The contractual term that BEST enforces this requirement is:
- Liquidated damages clause
- Incident notification clause with defined timeframes (Correct answer)
- Force majeure clause
- Limitation of liability clause
Correct answer: Incident notification clause with defined timeframes
An incident notification clause with specific timeframes (e.g., within 72 hours) contractually obligates vendors to promptly report security incidents.
Question 5: Which approach BEST allows a CISO to assess a vendor's real-world security posture without performing a direct on-site audit?
- Reviewing the vendor's website security policy
- Requesting and reviewing a third-party penetration test report or SOC 2 Type II attestation (Correct answer)
- Asking the vendor to self-certify compliance
- Checking the vendor's social media for security announcements
Correct answer: Requesting and reviewing a third-party penetration test report or SOC 2 Type II attestation
Third-party audit reports such as SOC 2 Type II or penetration test summaries provide independent, evidence-based insights into vendor security effectiveness.
Question 6: In a vendor risk management program, which document defines the specific security controls a vendor must implement and maintain?
- Master service agreement (MSA)
- Information security addendum or data processing agreement (Correct answer)
- Statement of work (SOW)
- Non-compete agreement
Correct answer: Information security addendum or data processing agreement
An information security addendum or data processing agreement details the specific security controls, obligations, and standards the vendor must maintain.
Question 7: A CISO discovers that a vendor's employees are using personal devices to access the organization's systems without authorization. This represents a violation of which policy type?
- Vendor acceptable use and access control policy (Correct answer)
- Physical security policy
- Software licensing policy
- Business continuity policy
Correct answer: Vendor acceptable use and access control policy
Vendor acceptable use and access control policies govern how vendor personnel may access organizational systems and prohibit use of unauthorized personal devices.
A CISO is selecting between two vendors: one holds ISO 27001 certification and the other provides a SOC 2 Type II report.
Which statement BEST describes the difference?