CGRC Third-Party Risk 5 — Questions and Answers
Question 1: A vendor provides your organization with a penetration test report conducted on their own systems. What is the primary limitation of this approach?
- Penetration tests are not recognized by compliance frameworks
- The report may lack independence since the vendor selected and scoped the test (Correct answer)
- Penetration tests do not cover application-layer vulnerabilities
- The report is only valid for 30 days after issuance
Correct answer: The report may lack independence since the vendor selected and scoped the test
Vendor-commissioned penetration tests may be scoped to exclude sensitive areas, reducing objectivity; an independent or customer-commissioned test provides greater assurance.
Question 2: Which practice helps organizations detect when a vendor's financial instability could threaten service continuity?
- Reviewing vendor SLA uptime statistics monthly
- Monitoring vendor credit ratings, financial filings, and news alerts (Correct answer)
- Conducting quarterly tabletop exercises with the vendor
- Reviewing vendor employee turnover rates annually
Correct answer: Monitoring vendor credit ratings, financial filings, and news alerts
Monitoring credit ratings, public financial filings, and news provides early warning signals of financial distress that could affect a vendor's ability to deliver services.
Question 3: What is the significance of a 'critical vendor' designation within a TPRM program?
- The vendor receives preferential pricing due to strategic importance
- The vendor undergoes enhanced due diligence, more frequent assessments, and has contingency plans (Correct answer)
- The vendor is exempt from standard security questionnaire requirements
- The vendor is automatically approved for multi-year contract renewals
Correct answer: The vendor undergoes enhanced due diligence, more frequent assessments, and has contingency plans
Critical vendors are subject to heightened scrutiny, more frequent risk reassessments, and must have documented contingency or substitution plans due to the impact their failure would have.
Question 4: Which regulatory requirement directly mandates that covered entities ensure their business associates implement appropriate safeguards for protected health information (PHI)?
- PCI DSS Requirement 12.8
- HIPAA Privacy and Security Rules (Correct answer)
- GDPR Article 28
- SOX Section 404
Correct answer: HIPAA Privacy and Security Rules
HIPAA requires covered entities to obtain satisfactory assurances from business associates — typically via a BAA — that PHI will be appropriately protected.
Question 5: When conducting a vendor risk assessment, which technique provides the most direct evidence of actual control implementation rather than documented policies?
- Reviewing the vendor's written security policy library
- Sending a vendor security questionnaire
- Performing an on-site inspection or technical control testing (Correct answer)
- Requesting the vendor's organizational chart
Correct answer: Performing an on-site inspection or technical control testing
On-site inspections and technical testing provide firsthand evidence that controls are actually implemented, rather than relying on the vendor's self-reported documentation.
Question 6: What is the purpose of including a 'flow-down clause' in vendor contracts?
- To reduce contract pricing when volume increases
- To require vendors to pass security and compliance obligations to their own subcontractors (Correct answer)
- To allow contract terms to automatically renew without renegotiation
- To flow excess budget from one project to another
Correct answer: To require vendors to pass security and compliance obligations to their own subcontractors
A flow-down clause requires a vendor to impose equivalent security and compliance requirements on any subcontractors it engages, extending protections down the supply chain.
Question 7: Which scenario best illustrates the concept of 'nth-party risk'?
- Your payroll vendor's cloud hosting provider suffers a breach that exposes your employee data (Correct answer)
- A vendor employee commits fraud against your organization
- Your organization fails to renew a vendor contract on time
- A vendor's product contains a known CVE that your team fails to patch
Correct answer: Your payroll vendor's cloud hosting provider suffers a breach that exposes your employee data
Nth-party risk occurs when a breach or failure at a sub-tier supplier (the cloud provider used by your vendor) propagates up to affect your organization, even though you have no direct relationship with that party.
A vendor provides your organization with a penetration test report conducted on their own systems.
What is the primary limitation of this approach?