Third-Party Vendor Risks Flashcards

1
Q

■ Products like routers and switches are composed of many components from various suppliers
■ Component tampering or untrustworthy vendors can introduce vulnerabilities
■ Rigorous supply chain assessments needed to trace origins and component integrity
■ Trusted foundry programs ensure secure manufacturing

A

Hardware Manufacturers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

■ An attack that targets a weaker link in the supply chain to gain access to a primary target
■ Exploit vulnerabilities in suppliers or service providers to access more secure systems

A

Supply Chain Attacks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

■ U.S. federal statute providing funding to boost semiconductor research and manufacturing in the U.S.
■ Aims to reduce reliance on foreign-made semiconductors, strengthen the domestic supply chain, and enhance security

A

CHIPS Act of 2022

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

● Essential components in a wide range of products, from smartphones and cars to medical devices and defense systems

A

Semiconductors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

■ Process to evaluate the security, reliability, and performance of external entities
■ Crucial due to interconnectivity and potential impact on multiple businesses

A

Vendor Assessments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Entities in Vendor Assessment

A

Vendors - provide goods or services
Suppliers - involved in production and delivery of products or parts
Managed Service Providers (MSPs) - Manage IT services on behalf of organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

● Simulated cyberattacks to identify vulnerabilities in supplier systems
■ Validates supplier’s cybersecurity practices and potential risks to your organization

A

Penetration Testing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

■ Contract provision allowing organizations to evaluate vendor’s internal processes for compliance
■ Ensures transparency and adherence to standards

A

Right-to-Audit Clause

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

■ Vendor’s self-assessment of practices against industry or organizational requirements
■ Demonstrates commitment to security and quality

A

Internal Audits

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

■ Evaluations conducted by third-party entities without a stake in the organization or vendor
■ Provides a neutral perspective on adherence to security or performance standards

A

Independent Assessments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

■ Assessment of an entire vendor supply chain for security and reliability
■ Ensures integrity of the vendor’s entire supply chain, including sources of parts or products

A

Supply Chain Analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

■ Guidelines for interaction between organization and vendors
■ Cover communication protocols, data sharing, and negotiation boundaries
■ Ensure productive and compliant interactions

A

Rules of Engagement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

■ Comprehensive documents filled out by potential vendors
■ Vendor questionnaires provide insights into operations, capabilities, and compliance
■ Standardized criteria for fair and informed decision-making

A

Vendor Questionnaires

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

■ Mechanism used to ensure that the chosen vendor still aligns with organizational needs and standards
■ Performance reviews assess deliverables against agreed-upon standards and objectives
■ Feedback loops

A

Vendor Monitoring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

● Versatile tool that formally establishes a relationship between two parties
● Defines roles, responsibilities, and consequences for non-compliance
● Specifies terms like payment structure, delivery timelines, and product specifications

A

Basic Contract

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

● Defines the standard of service a client can expect from a provider
● Includes performance benchmarks and penalties for deviations

Outlines the expectations regarding the quality, timelines, and scopes of services

A

Service Level Agreement (SLA)

17
Q

Formal, outlines specific responsibilities and roles

OR

Less binding, expresses mutual intent without detailed specifics

A

Memorandum of Agreement (MOA)

OR

Memorandum of Understanding (MOU)

18
Q

● Covers general terms of engagement across multiple transactions
● Used for recurring client relationships, supplemented by Statements of work

A

Master Service Agreement (MSA)

19
Q

● Specifies project details, deliverables, timelines, and milestones
● Provides in-depth project-related information

A

Statement of Work (SOW)

20
Q

● Ensures confidentiality of sensitive information shared during
negotiations
● Commitment to privacy, protecting proprietary data

A

Non-Disclosure Agreement (NDA)

21
Q

● Goes beyond basic contracts when two entities collaborate
● Outlines partnership nature, profit-sharing, decision-making, and exit strategies
● Defines ownership of intellectual property and revenue distribution

A

Business Partnership Agreement (BPA)
or
Joint Venture Agreement (JV)