Vendor Management Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Vendor Management flashcards as text
A CISO is developing a vendor exit strategy. Which element is MOST critical to include to protect the organization's sensitive information?
Answer: Data destruction or certified return procedures with proof of completion
A vendor exit strategy must include certified data destruction or return processes with documented proof to ensure sensitive information is not retained by the departing vendor.
Which procurement practice BEST reduces the risk of counterfeit or tampered hardware components entering the organization's supply chain?
Answer: Sourcing hardware from authorized resellers and implementing integrity verification upon receipt
Procuring from authorized resellers and verifying hardware integrity upon receipt reduces the risk of counterfeit or supply chain-compromised components.
Under the NIST Cybersecurity Framework, supply chain risk management (C-SCRM) is PRIMARILY associated with which function?
Answer: Identify
NIST CSF places supply chain risk management under the Identify function, as it involves understanding the risk landscape of suppliers and partners.
A CISO requires that all vendors complete a security questionnaire before contract award. This activity BEST represents which phase of vendor lifecycle management?
Answer: Vendor onboarding and due diligence
Completing security questionnaires prior to contract award is a due diligence activity performed during the vendor onboarding phase.
Which of the following BEST describes the purpose of a vendor scorecard in a third-party risk management program?
Answer: To provide a structured, measurable assessment of vendor performance across security and operational criteria
A vendor scorecard provides a structured framework to objectively measure and compare vendor performance against defined security, operational, and compliance criteria.
A CISO is negotiating a cloud services contract. Which provision is MOST important to address data residency requirements?
Answer: Contractual specification of geographic regions where data may be stored and processed
Specifying permissible geographic regions for data storage and processing in the contract directly addresses data residency and regulatory compliance requirements.
Which strategy BEST mitigates the risk of vendor personnel becoming a conduit for social engineering attacks against the organization?
Answer: Requiring vendor personnel to complete security awareness training aligned with organizational policies
Security awareness training for vendor personnel aligned to organizational policies reduces the likelihood of vendor staff being successfully targeted or manipulated in social engineering attacks.