Security Programme management and oversight 5.3 Flashcards

1
Q

Third Party Risk analysis

A

Important to conduct risk assessments on third party companies who through their work have access to important company data.

Perform risk assessments. Categorise risk by vendor and manage the risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Penetration testing.

A

Rules of engagement - important document defines rules of engagement during a pen test. Make sure everyone is aware of the parameters.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Right to audit clause

A

Right to audit clause ensures that any companies working with the organisation are aware that the organisation has a right to perform a security audit at any time.

Normally integrated into the contract itself.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Evidence of internal audits

A

Evaluate the effectiveness of security controls. May be required for compliance. Check for security controls and processes.

Access management, off boarding, password security. VPN controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Supply chain analysis

A

How we get a product from a vender to the customer.

Good opportunity to see where security vulnerabilities may exist in the supply chain.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Vendor selection process - Due diligence

A

Investigate and verify information. Financial status, pending or past legal issues. background checks and personal interviews.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Vendor monitoring

A

On going management with the vendor, reviews should occur on a regular basis.Different vendors may be checked for different indicators. Financial health check, IT security reviews, news articles.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Vendor selection process - conflict of interest.

A

A personal interest could compromise judgement
A potential partner also does business with your largest competition.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How to perform vendor monitoring

A

Send questionnaires to third parties.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Agreement types SLA

A

Service level agreement - Allows minimum terms for service provided. Uptime, Response time agreement, etc

Both companies are aware of the service level agreements and expectations between

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Agreement types - MOU

A

Memorandum of Understanding
Both sides agree in general to the contents of the memorandum. Usually states common goals, but not much more. Is informal and not a signed contract.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Agreement types - MOA

A

Both sides conditionally agree to the objectives. Can also be a legal document even without legal language.
Not a contract - does not provide legal enforcement.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Agreement types - MSA

A

Master Service Agreements. Legal Contract and agreement of terms. Many detailed negotiations happen here. Future projects will be based on this agreement.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Agreement types - WO or SOW

A

Work Order / Statement of Work
Specific list of items to be completed
Used in conjunction with the MSA
Details the scope of the job, location, deliverables, schedule, acceptance criteria.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Agreement types - NDA

A

Non disclosure agreement. Confidentiality agreement between parties. Information in the agreement should not be disclosed. Protects confidential information, trade secrets, business activities.

Unilateral (One-way) Bilateral (Mutual NDA)

Multilateral

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Common agreements - BPA

A

Business Partners Agreement (BPA)
Decision-making - who makes the business decision