Section 10.92 Vendor Assessment Flashcards

Objectives 2.2 Explain common threat vectors and attack surfaces. Objectives 2.3 Explain various types of vulnerabilities. Objectives 5.3 Explain the processes associated with third-party risk assessment and management.

1
Q

Vendor Assessments

A

Process to evaluate the security, reliability, and performance of external entities

Crucial due to interconnectivity and potential impact on multiple businesses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Entities in Vendor Assessment

Vendors

A

Provide goods or services to organizations

e.g Microsoft

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Entities in Vendor Assessment

Suppliers

A

Involved in production and delivery of products or parts

e.g Computer manufacturers might have multiple suppliers to provide processors, memory, harddrives etc

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Entities in Vendor Assessment

Managed Service Providers (MSPs)

A

Manage IT services on behalf of organisations

e.g AWS or Google Cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Entities in Vendor Assessment

Penetration Testing of Suppliers

A

Simulated cyberattacks to identify vulnerabilities in supplier systems

■ Validates supplier’s cybersecurity practices and potential risks to your organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Right-to-Audit Clause

A

Contract provision allowing organizations to evaluate vendor’s internal processes for compliance

■ Ensures transparency and adherence to standards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Internal Audits

A

Vendor’s self-assessment of practices against industry or organisational requirements

■ Demonstrates commitment to security and quality

Vendor to carry out its own internal audits

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Independent Assessments

A

Evaluations conducted by third-party entities without a stake in the organization or vendor

■ Provides a neutral perspective on adherence to security or performance standards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Supply Chain Analysis

A

Assessment of an entire vendor supply chain for security and reliability

■ Ensures integrity of the vendor’s entire supply chain, including sources of parts or products

How well did you know this?
1
Not at all
2
3
4
5
Perfectly