Lessons 25-29 Flashcards
THIRD-PARTY RISK MANAGEMENT
Is a composite of activities used to research and source third parties, conduct due diligence investigations, negotiate contracts, manage relationships, evaluate performance, and make payments
THIRD-PARTY OVERSIGHT
The implementation of strategies to manage uncertainty, identify vulnerabilities, and ensure compliance and continuity.
RIGHT TO AUDIT
A “right to audit” contract provision (clause) grants the contract holder the right to conduct or oversee an audit of the service provider’s facilities and practices.
MOU
memorandum of understanding is a non-binding document that outlines the intentions and areas of cooperation between parties
MOA
memorandum of agreement is a legally enforceable document that establishes a contractual relationship between parties.
BPA
business partner agreement is a comprehensive legal document that outlines the terms and conditions of a relationship between two or more businesses or entities
SLA
a service-level agreement codifies service and support requirements and may include incentives and or penalties.
MSA
a master services agreement outlines general terms and conditions. It serves as a framework for future agreements or projects between the parties.
SOW
a statement of work that defines tasks, deliverables, timelines, and performance expectations for a particular project or engagement between a client and a service provider
WO
a work order is transactional and used for individual service requests, often within the context of ongoing business relationships.
Data minimization-
approach limits data collection to only what is required to fulfill a specific purpose
RIGHT TO BE FORGOTTEN
Pertains to an individual’s right to have their personal information removed or deleted from online platforms, search engine results, or other publicity accessible sources.
Data controller-
determines the purposes for which, and the means by which, personal data is processed
Data processor
processes personal data on behalf of the data controller
Data protection officer
ensures that an organization is in compliance with privacy regulations as defined in the GDPR: independence is required.
Data masking
a technique used to protect sensitive data by replacing it with fictional or de-identified data
Tokenization
a technique to secure and desensitize data by replacing the original data with an unrelated value of the same length and format
Anonymization
the process in which individually identifiable data is altered in such a way that it no longer can be related back to a given individual