GRC Third-Party Risk Management 3 — Questions and Answers
Question 1: Which framework specifically provides a standardized questionnaire used widely in vendor security assessments?
- COBIT 2019
- Shared Assessments SIG (Standardized Information Gathering) (Correct answer)
- ISO 31000
- NIST SP 800-37
Correct answer: Shared Assessments SIG (Standardized Information Gathering)
The Shared Assessments SIG is a comprehensive, industry-standard questionnaire used to assess vendor security, privacy, and compliance controls.
Question 2: When a vendor relationship ends, which action is MOST critical from a data security standpoint?
- Archiving all vendor invoices for seven years
- Ensuring the vendor destroys or returns all organizational data per contract terms (Correct answer)
- Issuing a press release about the vendor change
- Conducting a vendor satisfaction survey
Correct answer: Ensuring the vendor destroys or returns all organizational data per contract terms
Data destruction or return during offboarding prevents residual data exposure and is a core requirement in most data processing agreements.
Question 3: A company relies on a single cloud provider for 85% of its IT infrastructure. This situation BEST exemplifies:
- Technology refresh risk
- Vendor concentration risk (Correct answer)
- Inherent residual risk
- Regulatory arbitrage risk
Correct answer: Vendor concentration risk
Vendor concentration risk occurs when over-reliance on a single vendor creates a single point of failure that could broadly disrupt operations.
Question 4: A SOC 2 Type II report differs from a SOC 2 Type I report in that it:
- Covers more Trust Service Criteria than Type I
- Tests controls over a period of time rather than at a single point in time (Correct answer)
- Is issued by the client organization rather than a third-party auditor
- Requires PCI DSS compliance as a prerequisite
Correct answer: Tests controls over a period of time rather than at a single point in time
SOC 2 Type II evaluates the operational effectiveness of controls over a defined period (usually 6–12 months), whereas Type I only assesses design at a point in time.
Question 5: Which approach to third-party risk assessment relies on real-time or near-real-time data feeds about a vendor's security posture from external sources?
- Questionnaire-based assessment
- Continuous monitoring / cyber risk ratings (Correct answer)
- On-site inspection audit
- Contractual self-attestation
Correct answer: Continuous monitoring / cyber risk ratings
Cyber risk rating platforms (e.g., BitSight, SecurityScorecard) continuously scan external-facing vendor infrastructure to provide ongoing security posture signals.
Question 6: Under GDPR, what is the relationship between a company that collects personal data and a vendor that processes it on the company's behalf?
- Both are considered data subjects
- The company is the Data Controller and the vendor is the Data Processor (Correct answer)
- The vendor is the Data Controller and the company is the Data Processor
- Both are Data Controllers with equal liability
Correct answer: The company is the Data Controller and the vendor is the Data Processor
GDPR defines the data-collecting company as the Controller and the vendor that processes data per the Controller's instructions as the Processor.
Question 7: What is the MAIN reason organizations require vendors to maintain their own business continuity plans (BCPs)?
- To reduce the organization's own BCP documentation burden
- To ensure the vendor can continue providing services during disruptions, protecting the organization's operations (Correct answer)
- To comply with vendor insurance requirements
- To allow the organization to audit vendor IT assets at any time
Correct answer: To ensure the vendor can continue providing services during disruptions, protecting the organization's operations
Vendor BCPs ensure service continuity during disruptions, which directly protects the dependent organization from cascading operational failures.
Which framework specifically provides a standardized questionnaire used widely in vendor security assessments?