CGRC Third-Party Risk 3 — Questions and Answers
Question 1: Which framework provides specific guidance for managing information security risks in supply chains, particularly relevant to US federal agencies?
- ISO 27001
- NIST SP 800-161 (Correct answer)
- COBIT 2019
- PCI DSS v4.0
Correct answer: NIST SP 800-161
NIST SP 800-161 addresses supply chain risk management (SCRM) practices for federal information systems and organizations.
Question 2: What is 'vendor concentration risk' in the context of third-party risk management?
- A vendor storing data in a single geographic location
- Over-reliance on a single vendor or small group of vendors for critical services (Correct answer)
- A vendor that focuses exclusively on one industry sector
- Risk arising from vendors that hold concentrated market share
Correct answer: Over-reliance on a single vendor or small group of vendors for critical services
Vendor concentration risk occurs when an organization depends too heavily on one vendor, meaning a failure or exit by that vendor could severely disrupt operations.
Question 3: Which metric in a vendor SLA is most relevant to operational resilience during a vendor outage?
- Mean Time to Detect (MTTD)
- Recovery Time Objective (RTO) (Correct answer)
- Annual Percentage Rate (APR)
- Control Effectiveness Rating (CER)
Correct answer: Recovery Time Objective (RTO)
RTO specifies how quickly a vendor's service must be restored after a disruption, directly affecting organizational resilience.
Question 4: A vendor refuses to allow an on-site audit due to confidentiality concerns. What is the most appropriate compensating measure?
- Accept the vendor's self-attestation without further action
- Terminate the contract immediately due to non-compliance
- Request a third-party audit report such as a SOC 2 Type II (Correct answer)
- Escalate to the vendor's board of directors
Correct answer: Request a third-party audit report such as a SOC 2 Type II
A SOC 2 Type II report, conducted by an independent auditor, provides assurance of vendor controls when a direct audit is not permitted.
Question 5: Under the FFIEC guidance, financial institutions must assess third-party risk through which phase of the vendor lifecycle?
- Only during initial onboarding
- Only when a security incident occurs
- Continuously throughout the entire vendor relationship lifecycle (Correct answer)
- Only at contract renewal
Correct answer: Continuously throughout the entire vendor relationship lifecycle
FFIEC guidance requires ongoing monitoring and assessment of third-party relationships throughout their entire lifecycle, not just at discrete checkpoints.
Question 6: Which type of third-party risk arises when a vendor's unethical practices damage your organization's public reputation?
- Operational risk
- Reputational risk (Correct answer)
- Strategic risk
- Compliance risk
Correct answer: Reputational risk
Reputational risk occurs when association with a vendor whose practices are unethical or controversial reflects negatively on your organization.
Question 7: A vendor achieves ISO 27001 certification. What does this certification confirm?
- The vendor has no security vulnerabilities in its systems
- The vendor's information security management system meets international standards (Correct answer)
- The vendor is compliant with all applicable data privacy laws
- The vendor's staff have passed background checks
Correct answer: The vendor's information security management system meets international standards
ISO 27001 certification confirms that a vendor's ISMS meets the internationally recognized standard for managing information security risks.
Which framework provides specific guidance for managing information security risks in supply chains, particularly relevant to US federal agencies?