Third-Party Vendor Compliance Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Third-Party Vendor Compliance flashcards as text
A vendor experiences a data breach involving your customers' PII. Under most US state breach notification laws, who bears primary notification responsibility to affected individuals?
Answer: Your organization, as the data controller/owner
Under most US state laws and GDPR, the data controller (your organization) is primarily responsible for notifying affected individuals, even when the breach occurred at a processor/vendor.
What does 'inherent risk' mean in the context of vendor risk scoring?
Answer: Risk that exists based on the nature of the vendor relationship before controls are assessed
Inherent risk reflects the baseline risk level of a vendor relationship — such as access to sensitive data or criticality — before any controls or mitigations are considered.
Which contractual provision ensures a vendor immediately informs you of a security incident affecting your data?
Answer: Breach notification requirement with a defined timeframe
A breach notification clause requires the vendor to report security incidents within a defined window (e.g., 72 hours), enabling timely response and regulatory compliance.
What is the significance of a vendor's penetration testing report in third-party due diligence?
Answer: It provides evidence that the vendor's systems have been independently tested for exploitable vulnerabilities
A penetration test report demonstrates that an independent party has actively attempted to exploit the vendor's systems, revealing real-world security weaknesses.
When evaluating a vendor's Business Continuity Plan (BCP), what should you specifically verify for your critical dependencies?
Answer: That your specific services and data are included in the BCP scope and tested recovery procedures
A BCP only protects your interests if the specific services and data you rely on are explicitly in scope with tested, documented recovery procedures.
A vendor is acquired by a competitor of your organization. What immediate compliance action should you take?
Answer: Review the contract for change-of-control clauses and reassess the vendor's risk profile
Change-of-control clauses may grant termination rights, and the acquisition could alter data access, confidentiality, or conflict-of-interest risks requiring immediate reassessment.
Which element is most critical to include in a Vendor Risk Register?
Answer: Risk rating, inherent and residual risk scores, and status of remediation actions
A Vendor Risk Register must capture risk ratings, both inherent and residual scores, and track open findings and remediation status to provide actionable risk visibility.