← All CSC Flashcard Decks

Third-Party Vendor Compliance Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Third-Party Vendor Compliance flashcards as text
  1. A vendor experiences a data breach involving your customers' PII. Under most US state breach notification laws, who bears primary notification responsibility to affected individuals?

    Answer: Your organization, as the data controller/owner

    Under most US state laws and GDPR, the data controller (your organization) is primarily responsible for notifying affected individuals, even when the breach occurred at a processor/vendor.

  2. What does 'inherent risk' mean in the context of vendor risk scoring?

    Answer: Risk that exists based on the nature of the vendor relationship before controls are assessed

    Inherent risk reflects the baseline risk level of a vendor relationship — such as access to sensitive data or criticality — before any controls or mitigations are considered.

  3. Which contractual provision ensures a vendor immediately informs you of a security incident affecting your data?

    Answer: Breach notification requirement with a defined timeframe

    A breach notification clause requires the vendor to report security incidents within a defined window (e.g., 72 hours), enabling timely response and regulatory compliance.

  4. What is the significance of a vendor's penetration testing report in third-party due diligence?

    Answer: It provides evidence that the vendor's systems have been independently tested for exploitable vulnerabilities

    A penetration test report demonstrates that an independent party has actively attempted to exploit the vendor's systems, revealing real-world security weaknesses.

  5. When evaluating a vendor's Business Continuity Plan (BCP), what should you specifically verify for your critical dependencies?

    Answer: That your specific services and data are included in the BCP scope and tested recovery procedures

    A BCP only protects your interests if the specific services and data you rely on are explicitly in scope with tested, documented recovery procedures.

  6. A vendor is acquired by a competitor of your organization. What immediate compliance action should you take?

    Answer: Review the contract for change-of-control clauses and reassess the vendor's risk profile

    Change-of-control clauses may grant termination rights, and the acquisition could alter data access, confidentiality, or conflict-of-interest risks requiring immediate reassessment.

  7. Which element is most critical to include in a Vendor Risk Register?

    Answer: Risk rating, inherent and residual risk scores, and status of remediation actions

    A Vendor Risk Register must capture risk ratings, both inherent and residual scores, and track open findings and remediation status to provide actionable risk visibility.