Third-Party Vendor Risk Flashcards

1
Q

Supply Chain Attacks

A

■ An attack that targets a weaker link in the supply chain to gain access to a
primary target
■ Exploit vulnerabilities in suppliers or service providers to access more secure
systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Vendor Due Diligence

Safeguarding Against Supply Chain Attacks

A

● Rigorous evaluation of vendor cybersecurity and supply chain practices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Regular Monitoring & Audits

Safeguarding Against Supply Chain Attacks

A

● Continuous monitoring and periodic audits of supply chains to detect
suspicious activities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Education and Collaboration

Safeguarding Against Supply Chain Attacks

A

● Sharing threat information and best practices within the industry
● Collaborating with organizations and industry groups for joint defense

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Incorporating Contractual Safeguards

Safeguarding Against Supply Chain Attacks

A

● Embedding cybersecurity clauses in contracts with suppliers or service
providers
● Ensuring adherence to security standards with legal repercussions for
non-compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Vendor Assessments

A

■ Process to evaluate the security, reliability, and performance of external entities
■ Crucial due to interconnectivity and potential impact on multiple businesses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Entities in Vendor Assessment

A

■ Vendors
● Provide goods or services to organizations
■ Suppliers
● Involved in production and delivery of products or parts
■ Managed Service Providers (MSPs)
● Manage IT services on behalf of organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Right-to-Audit Clause

A

■ Contract provision allowing organizations to evaluate vendor’s internal processes
for compliance
■ Ensures transparency and adherence to standards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Internal Audits

A

■ Vendor’s self-assessment of practices against industry or organizational
requirements
■ Demonstrates commitment to security and quality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Independent Assessments

A

■ Evaluations conducted by third-party entities without a stake in the organization
or vendor
■ Provides a neutral perspective on adherence to security or performance
standards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Supply Chain Analysis

A

■ Assessment of an entire vendor supply chain for security and reliability
■ Ensures integrity of the vendor’s entire supply chain, including sources of parts or
products

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Vendor Questionnaires

A

■ Vendor questionnaires provide insights into operations, capabilities, and
compliance
■ Standardized criteria for fair and informed decision-making

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Rules of Engagement

A

■ Cover communication protocols, data sharing, and negotiation boundaries
■ Ensure productive and compliant interactions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Vendor Monitoring

A

■ Mechanism used to ensure that the chosen vendor still aligns with organizational
needs and standards
■ Performance reviews assess deliverables against agreed-upon standards and
objectives
■ Feedback loops
● Involve a two-way communication channel where both the organization
and the vendor share feedback

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Service Level Agreement (SLA)

A

● Defines the standard of service a client can expect from a provider
● Includes performance benchmarks and penalties for deviations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Memorandum of Agreement (MOA)

A

Formal, outlines specific responsibilities and roles

17
Q

Memorandum of Understanding (MOU)

A

Less binding, expresses mutual intent without detailed specifics

18
Q

Master Service Agreement (MSA)

A

● Covers general terms of engagement across multiple transactions
● Used for recurring client relationships, supplemented by Statements of
Work

19
Q

Statement of Work (SOW)

A

● Specifies project details, deliverables, timelines, and milestones
● Provides in-depth project-related information

20
Q

Non-Disclosure Agreement (NDA)

A

● Ensures confidentiality of sensitive information shared during
negotiations
● Commitment to privacy, protecting proprietary data

21
Q

Business Partnership Agreement (BPA) or Joint Venture Agreement (JV)

A

● Goes beyond basic contracts when two entities collaborate
● Outlines partnership nature, profit-sharing, decision-making, and exit
strategies
● Defines ownership of intellectual property and revenue distribution