CSL CSL Vendor & Third-Party Risk Management 2 — Questions and Answers
Question 1: What is the primary purpose of a Vendor Risk Management (VRM) questionnaire?
- To negotiate better pricing with vendors
- To assess a vendor's security controls and practices against your requirements (Correct answer)
- To replace the need for vendor contracts
- To evaluate vendor financial health only
Correct answer: To assess a vendor's security controls and practices against your requirements
VRM questionnaires gather information about a vendor's security posture, policies, and controls to assess whether they meet the organization's security standards.
Question 2: Which industry standard framework provides a structure for managing information security risks throughout the supply chain?
- NIST SP 800-161 (Supply Chain Risk Management) (Correct answer)
- COBIT 2019
- ITIL 4 Foundation
- OWASP SAMM
Correct answer: NIST SP 800-161 (Supply Chain Risk Management)
NIST SP 800-161 provides guidelines specifically for identifying, assessing, and mitigating cybersecurity risks in supply chains and third-party relationships.
Question 3: An organization is onboarding a new payroll processing vendor. What minimum security requirement should be contractually required?
- Vendor must use open-source security tools
- Vendor must demonstrate encryption of data at rest and in transit (Correct answer)
- Vendor must be headquartered in the United States
- Vendor must employ only CISSP-certified staff
Correct answer: Vendor must demonstrate encryption of data at rest and in transit
Encryption of data at rest and in transit is a baseline security requirement that protects sensitive payroll data regardless of where it is stored or transmitted.
Question 4: What is the purpose of a concentration risk assessment in vendor management?
- To evaluate how many employees a vendor has
- To identify over-reliance on a single vendor for critical services (Correct answer)
- To assess vendor pricing competitiveness
- To measure vendor geographic distribution
Correct answer: To identify over-reliance on a single vendor for critical services
Concentration risk identifies situations where too many critical functions depend on a single vendor, creating a single point of failure that could disrupt operations.
Question 5: How should a cybersecurity leader handle a critical vendor who refuses to complete a security questionnaire?
- Accept the vendor without any security review
- Assess risk using available public information, certifications, and consider alternative vendors (Correct answer)
- Immediately terminate the vendor relationship
- Reduce the questionnaire to fewer questions
Correct answer: Assess risk using available public information, certifications, and consider alternative vendors
When a vendor refuses to cooperate, leaders should use available external evidence (SOC reports, certifications, news) to make a risk-based decision and evaluate alternatives.
Question 6: Which document should be established with a cloud vendor to specify how personal data is processed on your behalf?
- Non-disclosure agreement (NDA)
- Data Processing Agreement (DPA) (Correct answer)
- Master Service Agreement (MSA)
- Statement of Work (SOW)
Correct answer: Data Processing Agreement (DPA)
A Data Processing Agreement is required under GDPR and other privacy regulations when a vendor processes personal data as a data processor on your behalf.
What is the primary purpose of a Vendor Risk Management (VRM) questionnaire?