Third-party Vendor Risks Flashcards

1
Q

What are Third-party Vendor Risks?

A

Potential security and operational challenges from external collaborators

Encompasses vendors, suppliers, or service providers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are common Threat Vectors?

A

Paths attackers use to gain access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Define Attack Surfaces.

A

Points where an unauthorized user can try to enter.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are Hardware Vulnerabilities?

A

Components with vulnerabilities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are Software Vulnerabilities?

A

Applications with hidden backdoors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are Operational Vulnerabilities?

A

Lack of cybersecurity protocols.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a Vendor Assessment?

A

Process to evaluate the security, reliability, and performance of external entities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does Penetration Testing involve?

A

Simulated cyberattacks to identify vulnerabilities in supplier systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the Right-to-Audit Clause?

A

Contract provision allowing organizations to evaluate vendor’s internal processes for compliance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does Vendor Selection entail?

A

A meticulous selection process to evaluate potential vendors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the importance of Vendor Monitoring?

A

Ensures that the chosen vendor still aligns with organizational needs and standards.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a Service Level Agreement (SLA)?

A

Defines the standard of service a client can expect from a provider.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Fill in the blank: A ______ is a less binding agreement expressing mutual intent.

A

Memorandum of Understanding (MOU)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a Master Service Agreement (MSA)?

A

Covers general terms of engagement across multiple transactions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What does a Statement of Work (SOW) specify?

A

Project details, deliverables, timelines, and milestones.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a Non-Disclosure Agreement (NDA)?

A

Ensures confidentiality of sensitive information shared during negotiations.

17
Q

What are Supply Chain Attacks?

A

An attack that targets a weaker link in the supply chain to gain access to a primary target.

18
Q

What is the CHIPS Act of 2022?

A

U.S. federal statute providing funding to boost semiconductor research and manufacturing in the U.S.

19
Q

What are Trusted foundry programs?

A

Ensure secure manufacturing.

20
Q

What is the risk associated with Secondary/Aftermarket Sources?

A

Risk of acquiring counterfeit or tampered devices.

21
Q

What should be evaluated when selecting Service Providers/MSPs?

A

Data security measures, confidentiality and integrity, cybersecurity protocols.

22
Q

What does Vendor Due Diligence involve?

A

Rigorous evaluation of vendor cybersecurity and supply chain practices.

23
Q

What are Vendor Questionnaires?

A

Comprehensive documents filled out by potential vendors to provide insights into operations and compliance.

24
Q

What is an Independent Assessment?

A

Evaluations conducted by third-party entities without a stake in the organization or vendor.

25
What are the main components of Vendor Selection Process?
* Evaluating financial stability * Operational history * Client testimonials
26
What is the purpose of Rules of Engagement?
Guidelines for interaction between organization and vendors.
27
True or False: The Vendor Assessment process is crucial due to interconnectivity and potential impact on multiple businesses.
True
28
What is the primary focus of Supply Chain Analysis?
Assessment of an entire vendor supply chain for security and reliability.