Vendor Management Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Vendor Management flashcards as text
A CISO is selecting between two vendors: one holds ISO 27001 certification and the other provides a SOC 2 Type II report. Which statement BEST describes the difference?
Answer: ISO 27001 certifies an ISMS against a standard; SOC 2 Type II reports on operational effectiveness of controls over a period
ISO 27001 is a management system certification, while SOC 2 Type II is an attestation report covering the operational effectiveness of controls over a defined review period.
An organization relies on a single vendor for 80% of its critical IT infrastructure. Which risk concept does this BEST illustrate?
Answer: Vendor lock-in and single point of failure
Over-reliance on a single vendor creates vendor lock-in and a single point of failure, significantly elevating operational and continuity risk.
When a vendor handles cardholder data on behalf of an organization, which compliance framework DIRECTLY governs the vendor's security requirements?
Answer: PCI DSS
PCI DSS applies to any entity that stores, processes, or transmits cardholder data, including third-party vendors handling such data on behalf of merchants.
A CISO wants to ensure vendors promptly notify the organization of security incidents. The contractual term that BEST enforces this requirement is:
Answer: Incident notification clause with defined timeframes
An incident notification clause with specific timeframes (e.g., within 72 hours) contractually obligates vendors to promptly report security incidents.
Which approach BEST allows a CISO to assess a vendor's real-world security posture without performing a direct on-site audit?
Answer: Requesting and reviewing a third-party penetration test report or SOC 2 Type II attestation
Third-party audit reports such as SOC 2 Type II or penetration test summaries provide independent, evidence-based insights into vendor security effectiveness.
In a vendor risk management program, which document defines the specific security controls a vendor must implement and maintain?
Answer: Information security addendum or data processing agreement
An information security addendum or data processing agreement details the specific security controls, obligations, and standards the vendor must maintain.
A CISO discovers that a vendor's employees are using personal devices to access the organization's systems without authorization. This represents a violation of which policy type?
Answer: Vendor acceptable use and access control policy
Vendor acceptable use and access control policies govern how vendor personnel may access organizational systems and prohibit use of unauthorized personal devices.