โ† All GRC Flashcard Decks

Third-Party Risk Management Flashcards

7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Third-Party Risk Management flashcards as text
  1. Which metric is MOST useful for measuring how quickly an organization identifies and responds to vendor-related security incidents?

    Answer: Mean Time to Detect and Respond (MTTR/MTTD) for vendor incidents

    MTTD and MTTR quantify detection and response speed, which are critical efficiency metrics for third-party incident management.

  2. Which of the following is an example of residual risk in a vendor relationship?

    Answer: The risk remaining after all agreed-upon controls and mitigations have been implemented

    Residual risk is what remains after controls and mitigations are applied; it must be accepted, further mitigated, or transferred (e.g., via insurance).

  3. A technology vendor notifies your organization of a ransomware attack affecting their systems that store your customer data. What should be your organization's FIRST response step?

    Answer: Activate the vendor incident response playbook and notify your legal and security teams

    Activating the incident response playbook ensures a structured, timely response involving the right stakeholders, including legal and security teams.

  4. An inherent risk assessment of a vendor would evaluate risk:

    Answer: Before any mitigating controls or safeguards are applied

    Inherent risk represents the raw risk level associated with a vendor or activity before any controls are in place.

  5. Which of the following BEST supports a risk-based approach to vendor due diligence?

    Answer: Scaling the depth and frequency of assessments based on the vendor's risk tier and data access

    A risk-based approach tailors due diligence intensity to each vendor's risk profile, ensuring efficient use of assessment resources.

  6. What is the purpose of a vendor scorecard in ongoing third-party risk management?

    Answer: To track and visualize key performance and risk indicators for a vendor over time

    A vendor scorecard aggregates KPIs and KRIs into a dashboard that enables ongoing comparison of vendor performance and risk posture over time.

  7. Which contractual provision requires a vendor to notify the client within a specified timeframe if a data breach involving the client's data occurs?

    Answer: Data breach notification clause

    A data breach notification clause establishes the vendor's obligation to promptly inform the client of any security incident affecting the client's data, often aligning with regulatory timeframes.