CGRC Third-Party Risk 4 — Questions and Answers
Question 1: Which document should be established with a cloud service provider to define how the organization's data is protected, processed, and retained?
- Non-Disclosure Agreement (NDA)
- Shared Responsibility Matrix
- Data Processing Agreement (DPA) (Correct answer)
- Business Associate Agreement (BAA)
Correct answer: Data Processing Agreement (DPA)
A DPA contractually defines how the cloud provider processes, stores, and protects personal data on behalf of the organization.
Question 2: Which risk treatment option is most appropriate when a critical vendor cannot remediate a significant control gap but no alternative vendor exists?
- Risk avoidance — terminate the vendor relationship immediately
- Risk transfer — purchase cyber insurance to cover vendor-related losses
- Risk acceptance with enhanced monitoring and compensating controls (Correct answer)
- Risk sharing — partner with another organization to use the vendor jointly
Correct answer: Risk acceptance with enhanced monitoring and compensating controls
When avoidance is not feasible, accepting the risk while implementing compensating controls and heightened monitoring is the pragmatic treatment option.
Question 3: What is the purpose of a vendor inventory or vendor registry in a TPRM program?
- To track vendor invoice payments and accounts payable
- To maintain a centralized record of all vendors, their risk tiers, and contract statuses (Correct answer)
- To store copies of all vendor-produced deliverables
- To benchmark vendor performance against industry peers
Correct answer: To maintain a centralized record of all vendors, their risk tiers, and contract statuses
A vendor registry provides a single authoritative source of truth for all third-party relationships, risk classifications, and contractual details.
Question 4: An organization outsources its payroll processing. Which risk category is MOST relevant if the payroll vendor suffers a ransomware attack?
- Strategic risk
- Market risk
- Operational risk (Correct answer)
- Liquidity risk
Correct answer: Operational risk
A ransomware attack disrupting payroll processing represents operational risk, as it impairs a critical business function delivered by a third party.
Question 5: Which element distinguishes a SOC 2 Type II report from a SOC 2 Type I report?
- Type II covers more Trust Service Criteria than Type I
- Type II evaluates control effectiveness over a period of time, while Type I is point-in-time (Correct answer)
- Type II is performed by government auditors, while Type I uses private firms
- Type II includes financial controls, while Type I focuses on security only
Correct answer: Type II evaluates control effectiveness over a period of time, while Type I is point-in-time
A SOC 2 Type II report tests whether controls operated effectively over a specified review period (typically 6–12 months), whereas Type I only assesses whether controls are suitably designed at a single point in time.
Question 6: Which practice ensures that vendor access to organizational systems is removed promptly when no longer needed?
- Vendor onboarding checklist completion
- Just-in-time provisioning and automated deprovisioning (Correct answer)
- Annual vendor performance reviews
- Quarterly penetration testing of vendor systems
Correct answer: Just-in-time provisioning and automated deprovisioning
Just-in-time provisioning grants access only when needed, and automated deprovisioning ensures timely revocation, reducing the window of unauthorized access.
Question 7: Under the NIST Cybersecurity Framework, which function most directly addresses identifying and managing third-party risks?
- Protect
- Respond
- Identify (Correct answer)
- Recover
Correct answer: Identify
The Identify function of the NIST CSF includes supply chain risk management and establishing an understanding of third-party dependencies.
Which document should be established with a cloud service provider to define how the organization's data is protected, processed, and retained?