Section 10.93 Vendor Selection and Monitoring Flashcards

Objectives 2.2 Explain common threat vectors and attack surfaces. Objectives 2.3 Explain various types of vulnerabilities. Objectives 5.3 Explain the processes associated with third-party risk assessment and management.

1
Q

Vendor Selection and Monitoring

A

■ Due diligence

A rigorous evaluation that goes beyond surface-level credentials

● Includes the following
○ Evaluating financial stability
○ Operational history
○ Client testimonials
○ On-the-ground practices to ensure cultural alignment

Similar to hiring a team member

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Conflict of Interest

A

Arises when personal relationships could potentially cloud the judgement of individuals in vendor selection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Vendor Questionnaires

A

Vendor questionnaires provide insights into operations, capabilities, and compliance

■ Standardised criteria for fair and informed decision-making

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Rules of Engagement

A

Guidelines for interaction between organisation and vendors

■ Cover communication protocols, data sharing, and negotiation boundaries

■ Ensure vendor interactions are productive and compliant

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Vendor Continuous Monitoring

A

Monitoring: Mechanism used to ensure that the chosen vendor still aligns with organisational needs and standards

■ Performance reviews assess deliverables against agreed-upon standards and objectives

■ Feedback loops:
● Involve a two-way communication channel where both the organization and the vendor share feedback

How well did you know this?
1
Not at all
2
3
4
5
Perfectly