CTPRP Repertoire and Literature 3 — Questions and Answers
Question 1: SOC 2 reports, commonly reviewed during third-party due diligence, are based on which set of criteria?
- AICPA Trust Services Criteria (Correct answer)
- ISO 27001 control objectives
- NIST SP 800-53 control catalog
- PCI DSS requirements
Correct answer: AICPA Trust Services Criteria
SOC 2 reports are based on the AICPA Trust Services Criteria, which evaluate controls related to security, availability, processing integrity, confidentiality, and privacy.
Question 2: Which publication from the Federal Reserve, OCC, and FDIC provides interagency guidance on third-party relationships for banking organizations?
- Interagency Guidance on Third-Party Relationships: Risk Management (2023) (Correct answer)
- Regulation Y
- Basel III Accord
- Dodd-Frank Act Section 165
Correct answer: Interagency Guidance on Third-Party Relationships: Risk Management (2023)
In 2023, the Federal Reserve, OCC, and FDIC jointly issued interagency guidance providing a consistent framework for banks managing third-party relationship risks.
Question 3: In the context of TPRM literature, 'fourth-party risk' refers to:
- Risks arising from a vendor's own vendors and subcontractors (Correct answer)
- Risk from regulators auditing the organization
- Risk from internal IT outsourcing arrangements
- Risks introduced by mergers and acquisitions
Correct answer: Risks arising from a vendor's own vendors and subcontractors
Fourth-party risk refers to the risk an organization faces from its vendors' subcontractors (third parties to the third party), which may not be directly visible.
Question 4: The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires financial institutions to:
- Oversee service provider arrangements that involve customer financial data (Correct answer)
- Conduct annual penetration tests of all vendor systems
- Publish a list of all third-party vendors annually
- Obtain written attestation from vendors about GDPR compliance
Correct answer: Oversee service provider arrangements that involve customer financial data
The GLBA Safeguards Rule requires financial institutions to oversee their service providers to ensure appropriate safeguards are in place for customer financial information.
Question 5: ISO 31000:2018, the international risk management standard, defines risk as:
- The effect of uncertainty on objectives (Correct answer)
- The probability of a threat exploiting a vulnerability
- A quantified financial loss from an adverse event
- The likelihood multiplied by the impact of a hazard
Correct answer: The effect of uncertainty on objectives
ISO 31000:2018 defines risk as 'the effect of uncertainty on objectives,' a broader definition than probability-times-impact formulations.
Question 6: Which NIST publication provides a catalog of security and privacy controls used to assess and authorize federal information systems including those operated by contractors?
- NIST SP 800-53 (Correct answer)
- NIST SP 800-37
- NIST SP 800-171
- NIST SP 800-30
Correct answer: NIST SP 800-53
NIST SP 800-53 provides a comprehensive catalog of security and privacy controls applicable to federal systems and contractor environments under FedRAMP.
Question 7: The Payment Card Industry Data Security Standard (PCI DSS) Requirement 12.8 specifically addresses:
- Managing security risks associated with service providers (Correct answer)
- Encrypting cardholder data in transit
- Restricting physical access to cardholder data
- Implementing multi-factor authentication
Correct answer: Managing security risks associated with service providers
PCI DSS Requirement 12.8 mandates that organizations manage and monitor the security of third-party service providers that could impact the security of cardholder data.
SOC 2 reports, commonly reviewed during third-party due diligence, are based on which set of criteria?