IT Management: Managing Supply Chain and Vendors Flashcards
When evaluating new vendor, what would be the most appropriate minimum security standard for business to require of possible vendors?
compliance with the vendor’s own policies
What is VMS?
- vendor management system
- software solution that assists with the management and procurement of staffing services, hardware, software, and other needed products and services
- offer ordering convenience, order distribution, order training, consolidated billing, and more
What is the primary place where the minimum-security requirements for a third party should be documented?
contract or service-level agreement (SLA) established with that vendor
What’s Supply Chain Risk Management (SCRM)?
means to ensure that all the vendors or links in the supply chain are reliable, trustworthy, reputable organizations that disclose their practices and security requirements to their business partners
What’s third-party governance?
system of external entity oversight that may be mandated by law, regulation, industry standards, contractual obligation, or licensing requirements
What’s Documentation review?
process of reading the exchanged materials and verifying them against standards and expectations
Who has the discretion to determine which breaches or security changes result in a loss of Authorization to Operate (ATO)?
Authorizing Official (AO)
What are the four types of ATOs?
- authorization to operate
- common control authorization
- authorization to use
- denial of authorization