1.12 Applying Supply Chain and Risk Management (SCRM) Concepts Flashcards

1
Q

What is the primary goal of acquisitions?

A

To add value to an oranization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Who must security work with to understand the business rationale for acquiring new assets or services during acquisition?

A

The data owner.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What three things must security know about new assets to best protect them following an acquisition?

A

How the asset will be used | Who will access the asset | What types of data will the asset store or transfer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a Service Level Agreement (SLA) used for when participating with vendors or services?

A

Documents the security requirements to help the organizatrion evaluate different vendors and/or products against the security requirements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Stipulations such as how a vendor will continue to meet security requirements are often in the form of what contract addendum? Give an example.

A

Service Level Agreements | When a hospital gets a new vendor, an SLA is contracted to ensure HIPPA is always in compliance for their data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are Service Level Requirements (SLRs)? What may these requirements pertain to?

A

Additional organizational requirements that must be considered during an acquisition. | Detail service descriptions, Detail service level targets, dictate mutual responsibilities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Why are Service Level Requirements (SLR) important during the procurement process?

A

It defines the security service and service level targets that each potential supplier can be evaluated against.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

When a supplier is selected during the procurement proces, what will be used to inform the requirements documented in the Service Level Agreement (SLA)?

A

Service Level Requirements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What expectations and stipulations are included in a Service Level Agreement (SLA)?

A

Service Levels (performance levels) | Governance (Customer and provider know who is responsible for what) | Security (Expected security controls are in place by provides that speak to accountability and responsibility, though accountability is always belonging to the data owner) | Compliance with laws and regulations relating to the customer’s industry and place of business | Liability/Indemnification when any element of the SLA is not met or below standards.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the purpose of a Service Level Report (SLR)?

A

To identify how well expectations defined in the SLA are being met by the service provider.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Who typically provides Service Level Reports (SLRs)?

A

Typically, they are provided to the customer by the service provider.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What may be contained in a Service Level Report (SLR)?

A

Achievements of Metrics defined in the Service Level Agreement (SLA) | Identification of Issues | Reporting Channels | Management | Third-party SOC Reports, which provide independent verification and assurance that the terms of an SLA are being met.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

When would a third-party audit be beneficial to a customer?

A

When a customer is unable to evaluate all the facets of a service provider’s offering or when a customer wants an outside company to evaluate whether the terms of an Service Level Agreement (SLA) are being met.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly