Third-party Vendor Risks Flashcards

1
Q

What are Third-party Vendor Risks?

A

Potential security and operational challenges from external collaborators

Encompasses vendors, suppliers, or service providers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are common Threat Vectors?

A

Paths attackers use to gain access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Define Attack Surfaces.

A

Points where an unauthorized user can try to enter.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are Hardware Vulnerabilities?

A

Components with vulnerabilities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are Software Vulnerabilities?

A

Applications with hidden backdoors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are Operational Vulnerabilities?

A

Lack of cybersecurity protocols.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a Vendor Assessment?

A

Process to evaluate the security, reliability, and performance of external entities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does Penetration Testing involve?

A

Simulated cyberattacks to identify vulnerabilities in supplier systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the Right-to-Audit Clause?

A

Contract provision allowing organizations to evaluate vendor’s internal processes for compliance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does Vendor Selection entail?

A

A meticulous selection process to evaluate potential vendors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the importance of Vendor Monitoring?

A

Ensures that the chosen vendor still aligns with organizational needs and standards.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a Service Level Agreement (SLA)?

A

Defines the standard of service a client can expect from a provider.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Fill in the blank: A ______ is a less binding agreement expressing mutual intent.

A

Memorandum of Understanding (MOU)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a Master Service Agreement (MSA)?

A

Covers general terms of engagement across multiple transactions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What does a Statement of Work (SOW) specify?

A

Project details, deliverables, timelines, and milestones.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a Non-Disclosure Agreement (NDA)?

A

Ensures confidentiality of sensitive information shared during negotiations.

17
Q

What are Supply Chain Attacks?

A

An attack that targets a weaker link in the supply chain to gain access to a primary target.

18
Q

What is the CHIPS Act of 2022?

A

U.S. federal statute providing funding to boost semiconductor research and manufacturing in the U.S.

19
Q

What are Trusted foundry programs?

A

Ensure secure manufacturing.

20
Q

What is the risk associated with Secondary/Aftermarket Sources?

A

Risk of acquiring counterfeit or tampered devices.

21
Q

What should be evaluated when selecting Service Providers/MSPs?

A

Data security measures, confidentiality and integrity, cybersecurity protocols.

22
Q

What does Vendor Due Diligence involve?

A

Rigorous evaluation of vendor cybersecurity and supply chain practices.

23
Q

What are Vendor Questionnaires?

A

Comprehensive documents filled out by potential vendors to provide insights into operations and compliance.

24
Q

What is an Independent Assessment?

A

Evaluations conducted by third-party entities without a stake in the organization or vendor.

25
Q

What are the main components of Vendor Selection Process?

A
  • Evaluating financial stability
  • Operational history
  • Client testimonials
26
Q

What is the purpose of Rules of Engagement?

A

Guidelines for interaction between organization and vendors.

27
Q

True or False: The Vendor Assessment process is crucial due to interconnectivity and potential impact on multiple businesses.

28
Q

What is the primary focus of Supply Chain Analysis?

A

Assessment of an entire vendor supply chain for security and reliability.