CSL CSL Vendor & Third-Party Risk Management 1 — Questions and Answers
Question 1: What is the first step in establishing a third-party risk management (TPRM) program?
- Send security questionnaires to all vendors immediately
- Create an inventory and risk tiering of all third-party relationships (Correct answer)
- Require all vendors to obtain ISO 27001 certification
- Conduct penetration tests on vendor systems
Correct answer: Create an inventory and risk tiering of all third-party relationships
Risk tiering classifies vendors by the sensitivity of data they access and their business criticality, allowing resources to be focused on the highest-risk relationships.
Question 2: Which contractual mechanism gives an organization the right to assess a vendor's security controls directly?
- Non-disclosure agreement (NDA)
- Right-to-audit clause (Correct answer)
- Service level agreement (SLA)
- Data processing addendum (DPA)
Correct answer: Right-to-audit clause
A right-to-audit clause contractually entitles the organization to conduct or commission security assessments of the vendor's environment.
Question 3: A SaaS vendor suffers a breach affecting your organization's data. Under GDPR, who bears primary responsibility for notifying affected individuals?
- The SaaS vendor as the data processor
- Your organization as the data controller (Correct answer)
- The cloud platform hosting the SaaS application
- The cybersecurity insurer
Correct answer: Your organization as the data controller
Under GDPR, the data controller (your organization) is responsible for notifying supervisory authorities and affected individuals, regardless of where the breach originated.
Question 4: What does a SOC 2 Type II report demonstrate about a cloud vendor?
- The vendor has passed a one-time security assessment
- The vendor's controls operated effectively over a sustained audit period (Correct answer)
- The vendor is certified under ISO 27001
- The vendor complies with PCI DSS requirements
Correct answer: The vendor's controls operated effectively over a sustained audit period
SOC 2 Type II audits cover a period of time (typically 6–12 months), demonstrating that security controls were operating consistently, not just present at one point.
Question 5: Which risk most commonly arises from fourth-party (sub-processor) relationships in vendor management?
- Direct contractual liability to the primary vendor
- Hidden dependencies that inherit the primary vendor's risk without direct oversight (Correct answer)
- Increased SLA performance guarantees
- Reduced data processing costs
Correct answer: Hidden dependencies that inherit the primary vendor's risk without direct oversight
Fourth-party risks arise when your vendors outsource to sub-processors you have no direct visibility into, creating blind spots in your supply chain risk exposure.
Question 6: A cybersecurity leader is reviewing vendor contracts. Which clause specifically protects the organization if a vendor experiences a security incident?
- Indemnification and breach notification clauses (Correct answer)
- Termination for convenience clause
- Intellectual property ownership clause
- Warranty and fitness-for-purpose clause
Correct answer: Indemnification and breach notification clauses
Indemnification clauses allocate financial liability for security incidents, while breach notification clauses require the vendor to report incidents within a defined timeframe.
What is the first step in establishing a third-party risk management (TPRM) program?