CTPRP Third-Party Risk Assessment and Due Diligence 2 — Questions and Answers
Question 1: Which standard provides a framework for information security management systems and is commonly requested from vendors in due diligence?
- ISO/IEC 27001 (Correct answer)
- SOC 2 Type II
- PCI DSS
- HIPAA
Correct answer: ISO/IEC 27001
ISO/IEC 27001 is the internationally recognized standard for information security management systems and is frequently requested as evidence of security controls during vendor due diligence.
Question 2: A SOC 2 Type II report differs from a SOC 2 Type I report in that it:
- Covers effectiveness of controls over a period of time, not just a point in time (Correct answer)
- Covers financial controls rather than security controls
- Is issued by the client organization rather than an auditor
- Only applies to cloud service providers
Correct answer: Covers effectiveness of controls over a period of time, not just a point in time
SOC 2 Type II reports assess the operational effectiveness of controls over a defined review period (typically 6–12 months), whereas Type I assesses controls at a single point in time.
Question 3: What is the key objective of a vendor's Business Continuity Plan (BCP) review during due diligence?
- To verify the vendor can maintain services during disruptions (Correct answer)
- To assess the vendor's financial profitability
- To evaluate the vendor's employee retention rates
- To confirm the vendor's marketing strategy
Correct answer: To verify the vendor can maintain services during disruptions
Reviewing a vendor's BCP ensures that the vendor has documented plans to sustain critical services during disruptions, protecting your organization from supply chain interruptions.
Question 4: What is 'concentration risk' in third-party risk management?
- Over-reliance on a single vendor or a small group of vendors for critical services (Correct answer)
- A vendor's risk score being too high for onboarding
- The risk of a vendor concentrating too many employees in one office
- The risk from multiple contracts with the same vendor department
Correct answer: Over-reliance on a single vendor or a small group of vendors for critical services
Concentration risk occurs when an organization depends heavily on one or few vendors for critical functions, amplifying the impact if that vendor fails or is disrupted.
Question 5: Which of the following is the best indicator that a vendor's security posture is maturing over time?
- Demonstrated remediation of previously identified control gaps (Correct answer)
- Increasing number of employees in their IT department
- Growing annual revenue of the vendor
- Longer tenure of the vendor's CISO
Correct answer: Demonstrated remediation of previously identified control gaps
A vendor that consistently remediates identified control gaps over successive assessments demonstrates active improvement and maturing security capabilities.
Question 6: When evaluating a cloud vendor's data security controls, which document best details where and how customer data is stored and processed?
- Data Processing Agreement (DPA) (Correct answer)
- Master Service Agreement (MSA)
- Non-Disclosure Agreement (NDA)
- Service-Level Agreement (SLA)
Correct answer: Data Processing Agreement (DPA)
A Data Processing Agreement specifies the roles, responsibilities, and obligations for how the vendor will process, store, and protect customer data in compliance with applicable regulations.
Which standard provides a framework for information security management systems and is commonly requested from vendors in due diligence?