IT Management: Managing Supply Chain and Vendors Flashcards

1
Q

When evaluating new vendor, what would be the most appropriate minimum security standard for business to require of possible vendors?

A

compliance with the vendor’s own policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is VMS?

A
  • vendor management system
  • software solution that assists with the management and procurement of staffing services, hardware, software, and other needed products and services
  • offer ordering convenience, order distribution, order training, consolidated billing, and more
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the primary place where the minimum-security requirements for a third party should be documented?

A

contract or service-level agreement (SLA) established with that vendor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What’s Supply Chain Risk Management (SCRM)?

A

means to ensure that all the vendors or links in the supply chain are reliable, trustworthy, reputable organizations that disclose their practices and security requirements to their business partners

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What’s third-party governance?

A

system of external entity oversight that may be mandated by law, regulation, industry standards, contractual obligation, or licensing requirements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What’s Documentation review?

A

process of reading the exchanged materials and verifying them against standards and expectations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Who has the discretion to determine which breaches or security changes result in a loss of Authorization to Operate (ATO)?

A

Authorizing Official (AO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the four types of ATOs?

A
  • authorization to operate
  • common control authorization
  • authorization to use
  • denial of authorization
How well did you know this?
1
Not at all
2
3
4
5
Perfectly