CCSP: Domain 5 - Vendor Management Flashcards

1
Q

What are the steps in the vendor management lifecycle? (4)

A
  1. vendor selection
  2. onboarding
  3. maintenance
  4. offboarding
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the common clauses and sections found in cloud service agreements? (8)

A
  1. definition of terms
  2. performance metrics and remedies
  3. data ownership
  4. compliance obligations
  5. assurance
  6. indemnification
  7. termination
  8. litigation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Why does a contract need definition of terms?

A

it has to be clear what do the used terms mean; e.g. what exactly is meant by outage?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are Service Level Management practices?

A

cloud customer monitoring vendor’s compliance with SLAs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What should a contract specify, when it comes to data ownership?

A

customer retains any data that it uses in the cloud service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What do cloud vendor compliance obligations entail in a contract?

A

the contract needs to include all the compliance regulations and laws that the cloud customer is subject to and therefore cloud provider needs to be too

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does assurance entail in cloud contracts?

A

ability to implement assurance measures that allow to verify, that the vendor is living up to its obligations under the contract

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does litigation need to cover in contracts?

A

the jurisdiction of the litigation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does scoping mean in the context of engaging and selecting cloud vendor?

A

term used for only including departments or units impacted by the cloud engagement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

When choosing a CSP, it is important to evaluate several factors to understand the risk. What are the questions that need to be asked?

A
  1. Is the provider subject to takeover or acquisition?
  2. How financially stable is the provider?
  3. In what legal jurisdictions are the provider’s offices located?
  4. Are there outstanding lawsuits against the provider?
  5. What pricing protections are in place for services contracted?
  6. How will a provider satisfy any regulatory or legal compliance requiremetns?
  7. What does failover, backup and recovery look like for a provider?
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What framework is provided by CSA to evaluate risk in CSPs?

A

CSA STAR (Security, Trust, Assurance, Risk)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does the CSA STAR (Security, Trust, Assurance, Risk) contain?

A

evaluations of cloud services against the CSA’s cloud control matrix (CCM)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What kind of assessments can be used with CSA STAR (Security, Trust, Assurance, Risk)?

A

self-assessment or third-party assessment; affects the level of assurance (self - low, 3rd party - high)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What wieght does the CSA STAR (Security, Trust, Assurance, Risk) have?

A

lightweight, lower assurance cetification for the CSPs that use it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is island hopping attack?

A

attack on an organization through a compromised vendor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Vendor management overlaps with what practices?

A

Supply Chain Risk Management (SCRM)

17
Q

Vendor management includes activities related to what type of risks?

A

operational