CSL Cybersecurity Contract Law & Vendor Management 1 — Questions and Answers
Question 1: What contractual provision specifically allocates cybersecurity responsibilities between a company and its third-party vendor?
- Indemnification clause
- Security addendum or exhibit (Correct answer)
- Non-disclosure agreement
- Force majeure clause
Correct answer: Security addendum or exhibit
A security addendum or exhibit attached to a contract specifically outlines each party's cybersecurity responsibilities, required controls, and compliance obligations.
Question 2: Under 'flow-down' provisions in vendor contracts, what is the primary purpose?
- To reduce the vendor's liability cap
- To ensure subcontractors meet the same security requirements as the primary vendor (Correct answer)
- To transfer all cybersecurity risk to the client
- To eliminate the client's audit rights
Correct answer: To ensure subcontractors meet the same security requirements as the primary vendor
Flow-down provisions require that subcontractors and sub-vendors adhere to the same cybersecurity standards and requirements imposed on the primary vendor.
Question 3: What is a Service Level Agreement (SLA) in the context of cybersecurity vendor contracts?
- A government regulation mandating minimum security standards
- A contractual commitment defining measurable performance metrics including uptime and incident response times (Correct answer)
- An insurance policy covering data breaches
- A certification standard for cybersecurity professionals
Correct answer: A contractual commitment defining measurable performance metrics including uptime and incident response times
An SLA is a contractual agreement that defines measurable service standards, including security-related metrics like uptime, incident response times, and breach notification windows.
Question 4: Which legal doctrine may hold a company liable for cybersecurity failures of its vendors?
- Business judgment rule
- Negligent supervision or negligent selection (Correct answer)
- Res judicata
- Statute of limitations
Correct answer: Negligent supervision or negligent selection
Under negligent supervision or negligent selection doctrines, companies can be held liable if they fail to properly vet or oversee vendors who cause cybersecurity harm.
Question 5: What is a 'right to audit' clause in a cybersecurity vendor contract?
- A provision allowing the vendor to audit the client's security practices
- A provision granting the contracting party the right to inspect the vendor's security controls (Correct answer)
- A government mandate requiring annual third-party security audits
- A provision limiting the vendor's liability to audit-related costs
Correct answer: A provision granting the contracting party the right to inspect the vendor's security controls
A right to audit clause gives the contracting party (typically the client) the contractual right to inspect, test, or audit the vendor's security controls and practices.
Question 6: In vendor contracts, what does a 'limitation of liability' clause typically cap?
- The number of security incidents a vendor must report
- The maximum monetary damages a vendor will pay in the event of a breach (Correct answer)
- The scope of the vendor's cybersecurity obligations
- The duration of the contractual relationship
Correct answer: The maximum monetary damages a vendor will pay in the event of a breach
Limitation of liability clauses cap the maximum amount a vendor is financially responsible for, typically tied to fees paid under the contract, limiting exposure in breach scenarios.
Question 7: What is a Master Service Agreement (MSA) in the context of cybersecurity vendor relationships?
- A government-issued cybersecurity framework
- A comprehensive foundational contract governing the overall terms of the relationship between parties (Correct answer)
- A single-project contract for a one-time security assessment
- An insurance agreement covering cybersecurity incidents
Correct answer: A comprehensive foundational contract governing the overall terms of the relationship between parties
An MSA is a foundational contract establishing overall terms governing a long-term vendor relationship, with individual Statements of Work (SOWs) addressing specific projects or services.
What contractual provision specifically allocates cybersecurity responsibilities between a company and its third-party vendor?