Third-Party Risk Management Flashcards
7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Third-Party Risk Management flashcards as text
Which framework specifically provides a standardized questionnaire used widely in vendor security assessments?
Answer: Shared Assessments SIG (Standardized Information Gathering)
The Shared Assessments SIG is a comprehensive, industry-standard questionnaire used to assess vendor security, privacy, and compliance controls.
When a vendor relationship ends, which action is MOST critical from a data security standpoint?
Answer: Ensuring the vendor destroys or returns all organizational data per contract terms
Data destruction or return during offboarding prevents residual data exposure and is a core requirement in most data processing agreements.
A company relies on a single cloud provider for 85% of its IT infrastructure. This situation BEST exemplifies:
Answer: Vendor concentration risk
Vendor concentration risk occurs when over-reliance on a single vendor creates a single point of failure that could broadly disrupt operations.
A SOC 2 Type II report differs from a SOC 2 Type I report in that it:
Answer: Tests controls over a period of time rather than at a single point in time
SOC 2 Type II evaluates the operational effectiveness of controls over a defined period (usually 6–12 months), whereas Type I only assesses design at a point in time.
Which approach to third-party risk assessment relies on real-time or near-real-time data feeds about a vendor's security posture from external sources?
Answer: Continuous monitoring / cyber risk ratings
Cyber risk rating platforms (e.g., BitSight, SecurityScorecard) continuously scan external-facing vendor infrastructure to provide ongoing security posture signals.
Under GDPR, what is the relationship between a company that collects personal data and a vendor that processes it on the company's behalf?
Answer: The company is the Data Controller and the vendor is the Data Processor
GDPR defines the data-collecting company as the Controller and the vendor that processes data per the Controller's instructions as the Processor.
What is the MAIN reason organizations require vendors to maintain their own business continuity plans (BCPs)?
Answer: To ensure the vendor can continue providing services during disruptions, protecting the organization's operations
Vendor BCPs ensure service continuity during disruptions, which directly protects the dependent organization from cascading operational failures.