CSC Third-Party Vendor Compliance 3 — Questions and Answers
Question 1: A contract with a cloud vendor lacks a right-to-audit clause. What risk does this create?
- The vendor can increase prices without notice
- You cannot independently verify the vendor's security controls (Correct answer)
- The vendor gains access to your internal systems
- Data residency requirements become unenforceable
Correct answer: You cannot independently verify the vendor's security controls
Without a right-to-audit clause, your organization must rely solely on the vendor's self-reported security posture with no contractual mechanism for independent verification.
Question 2: Which metric best indicates a vendor's ability to restore services after a disruption?
- Mean Time Between Failures (MTBF)
- Recovery Time Objective (RTO) (Correct answer)
- Change Failure Rate (CFR)
- Patch Cadence Score
Correct answer: Recovery Time Objective (RTO)
The Recovery Time Objective (RTO) defines the maximum acceptable time for a vendor to restore services after an outage, directly measuring resilience capability.
Question 3: What is 'vendor lock-in risk' from a compliance perspective?
- A vendor that locks its office doors after hours
- Dependency on a single vendor making it difficult to switch providers if compliance issues arise (Correct answer)
- A vendor that requires exclusive contracts
- Over-reliance on vendor-provided compliance documentation
Correct answer: Dependency on a single vendor making it difficult to switch providers if compliance issues arise
Vendor lock-in creates a compliance risk because an organization cannot easily exit a non-compliant vendor relationship if switching costs or technical barriers are prohibitively high.
Question 4: A SaaS vendor stores data in a country with weak privacy laws. Which control best mitigates this data residency risk?
- Requiring the vendor to obtain ISO 27001 certification
- Including contractual data localization requirements specifying approved jurisdictions (Correct answer)
- Performing quarterly vulnerability scans on the vendor's systems
- Requesting the vendor's employee training records
Correct answer: Including contractual data localization requirements specifying approved jurisdictions
Contractual data localization clauses legally bind the vendor to store and process data only in jurisdictions that meet your compliance requirements.
Question 5: Under PCI DSS, what obligation does a merchant have when a third-party service provider handles cardholder data?
- No obligation — PCI DSS only applies to the merchant's internal systems
- The merchant must verify the service provider is PCI DSS compliant (Correct answer)
- The merchant must co-locate servers with the service provider
- The merchant must assume full liability for any breach
Correct answer: The merchant must verify the service provider is PCI DSS compliant
PCI DSS Requirement 12.8 mandates that merchants maintain a list of service providers and verify their compliance status at least annually.
Question 6: What is the primary purpose of a vendor offboarding process from a cybersecurity perspective?
- To collect final invoices
- To revoke all vendor access and retrieve or destroy organizational data (Correct answer)
- To archive the vendor's SOC 2 reports
- To transfer vendor employees to internal roles
Correct answer: To revoke all vendor access and retrieve or destroy organizational data
Secure offboarding ensures that vendor access credentials are revoked, shared data is returned or destroyed, and no residual access vectors remain.
Question 7: Which approach provides continuous visibility into a vendor's security posture between formal annual assessments?
- Requesting updated questionnaires monthly
- Using automated security ratings platforms that monitor vendor attack surface signals (Correct answer)
- Hiring a dedicated analyst to monitor each vendor
- Requiring weekly status calls with vendor security teams
Correct answer: Using automated security ratings platforms that monitor vendor attack surface signals
Security ratings platforms (e.g., BitSight, SecurityScorecard) provide continuous, automated monitoring of external signals like open ports, patching cadence, and data breaches.
A contract with a cloud vendor lacks a right-to-audit clause.
What risk does this create?