CTPRP Information Security and Privacy Risk in Third-Party Relationships — Questions and Answers
Question 1: When assessing a vendor's information security posture, which document provides the MOST comprehensive view of their control environment?
- The vendor's marketing brochure describing their security features
- A completed Standardized Information Gathering (SIG) questionnaire with supporting evidence (Correct answer)
- A single-page attestation letter signed by the vendor's CEO
- The vendor's ISO 9001 quality management certificate
Correct answer: A completed Standardized Information Gathering (SIG) questionnaire with supporting evidence
The SIG (developed by Shared Assessments) is the industry-standard questionnaire for third-party information security assessments. It covers dozens of control domains and is designed to be accompanied by supporting evidence. A marketing brochure is promotional, a CEO attestation lacks depth, and ISO 9001 covers quality management — not information security.
Question 2: A vendor will process personally identifiable information (PII) on behalf of your organization. Which contractual clause is MOST critical from a privacy risk perspective?
- A most-favored-nation pricing clause
- A data processing agreement (DPA) specifying permissible uses and breach notification timelines (Correct answer)
- A non-solicitation clause preventing the vendor from hiring your staff
- A liquidated damages clause tied to project delivery milestones
Correct answer: A data processing agreement (DPA) specifying permissible uses and breach notification timelines
A Data Processing Agreement (DPA) is required under most major privacy frameworks (GDPR, CCPA, etc.) when a vendor acts as a data processor. It defines permissible uses of data, security requirements, breach notification obligations, and data subject rights support. This is the foundational privacy contract clause for any PII-handling vendor.
Question 3: Which of the following BEST describes the difference between a Type I and Type II SOC 2 report?
- Type I covers security only; Type II covers all five Trust Service Criteria
- Type I assesses control design at a point in time; Type II tests operating effectiveness over a period (Correct answer)
- Type I is conducted by the vendor internally; Type II requires an external auditor
- Type I applies to cloud vendors only; Type II applies to on-premise vendors
Correct answer: Type I assesses control design at a point in time; Type II tests operating effectiveness over a period
A SOC 2 Type I report evaluates whether controls are suitably designed at a specific point in time. A SOC 2 Type II report — preferred by most third-party risk programs — tests whether those controls operated effectively over a defined review period (typically 6–12 months). The Type II provides much stronger assurance because it demonstrates sustained control operation.
Question 4: Your organization shares customer financial data with a vendor that subsequently suffers a ransomware attack. Under a mature third-party risk program, who bears primary responsibility for notifying affected customers?
- The vendor, since the breach occurred in their environment
- The originating organization, as the data controller, in accordance with applicable regulations (Correct answer)
- The cybersecurity insurance carrier that covered the incident
- CISA, as the federal agency responsible for critical infrastructure incidents
Correct answer: The originating organization, as the data controller, in accordance with applicable regulations
Under most privacy and data protection laws (e.g., GDPR, state breach notification laws), the data controller — the organization that collected the customer data — retains responsibility for breach notification obligations, even when the breach occurs at a vendor (data processor). The contract should require the vendor to promptly notify the controller so that the controller can fulfill its regulatory duties.
Question 5: Which of the following is a key output of a vendor's penetration test that a third-party risk professional should review?
- A list of all employees who participated in the test
- The total cost billed by the penetration testing firm
- An executive summary of vulnerabilities found, their severity ratings, and remediation status (Correct answer)
- The vendor's full source code submitted for review
Correct answer: An executive summary of vulnerabilities found, their severity ratings, and remediation status
The risk-relevant output of a penetration test is the findings report — specifically the vulnerabilities discovered, their CVSS or similar severity ratings, and whether they have been remediated or mitigated. This allows the third-party risk professional to assess whether the vendor has addressed material weaknesses. Employee lists, invoices, and source code are not standard assessment artifacts.
Question 6: The principle of 'data minimization' in the context of third-party risk management means:
- Vendors should store data in the smallest physical data centers possible
- Organizations should share only the minimum amount of personal data with vendors that is necessary to fulfill the service (Correct answer)
- Vendors must compress all files to reduce storage costs
- Risk assessments should be limited to no more than ten questions
Correct answer: Organizations should share only the minimum amount of personal data with vendors that is necessary to fulfill the service
Data minimization is a privacy principle enshrined in GDPR and other regulations requiring that only data strictly necessary for the specified purpose be collected or shared. When applied to third-party relationships, it limits the amount of sensitive data exposed to vendor environments, directly reducing privacy and security risk.
When assessing a vendor's information security posture, which document provides the MOST comprehensive view of their control environment?