Third-Party Vendor Compliance Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Third-Party Vendor Compliance flashcards as text
A contract with a cloud vendor lacks a right-to-audit clause. What risk does this create?
Answer: You cannot independently verify the vendor's security controls
Without a right-to-audit clause, your organization must rely solely on the vendor's self-reported security posture with no contractual mechanism for independent verification.
Which metric best indicates a vendor's ability to restore services after a disruption?
Answer: Recovery Time Objective (RTO)
The Recovery Time Objective (RTO) defines the maximum acceptable time for a vendor to restore services after an outage, directly measuring resilience capability.
What is 'vendor lock-in risk' from a compliance perspective?
Answer: Dependency on a single vendor making it difficult to switch providers if compliance issues arise
Vendor lock-in creates a compliance risk because an organization cannot easily exit a non-compliant vendor relationship if switching costs or technical barriers are prohibitively high.
A SaaS vendor stores data in a country with weak privacy laws. Which control best mitigates this data residency risk?
Answer: Including contractual data localization requirements specifying approved jurisdictions
Contractual data localization clauses legally bind the vendor to store and process data only in jurisdictions that meet your compliance requirements.
Under PCI DSS, what obligation does a merchant have when a third-party service provider handles cardholder data?
Answer: The merchant must verify the service provider is PCI DSS compliant
PCI DSS Requirement 12.8 mandates that merchants maintain a list of service providers and verify their compliance status at least annually.
What is the primary purpose of a vendor offboarding process from a cybersecurity perspective?
Answer: To revoke all vendor access and retrieve or destroy organizational data
Secure offboarding ensures that vendor access credentials are revoked, shared data is returned or destroyed, and no residual access vectors remain.
Which approach provides continuous visibility into a vendor's security posture between formal annual assessments?
Answer: Using automated security ratings platforms that monitor vendor attack surface signals
Security ratings platforms (e.g., BitSight, SecurityScorecard) provide continuous, automated monitoring of external signals like open ports, patching cadence, and data breaches.