← All CSC Flashcard Decks

Third-Party Vendor Compliance Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Third-Party Vendor Compliance flashcards as text
  1. What is 'concentration risk' in third-party vendor management?

    Answer: Over-reliance on a single vendor or a small group of vendors for critical functions

    Concentration risk arises when too many critical business functions depend on a single vendor or provider, creating a single point of failure that can cascade across the organization.

  2. Under the NIST Cybersecurity Framework, which function most directly addresses third-party risk identification?

    Answer: Identify

    The NIST CSF 'Identify' function includes supply chain risk management and asset management activities, which are foundational to recognizing third-party risks.

  3. A vendor's ISO 27001 certificate has expired. What does this mean for your risk assessment?

    Answer: The vendor's ISMS has not been re-audited and recertification status is unknown

    An expired ISO 27001 certificate means the vendor has not recently demonstrated to a certification body that their Information Security Management System continues to meet standard requirements.

  4. What is the primary goal of a vendor exit strategy documented in a contract?

    Answer: To ensure continuity of service and data return/destruction if the vendor relationship ends

    A well-defined exit strategy ensures your data is retrievable or destroyed and that service continuity is maintained through transition, protecting operations regardless of why the relationship ends.

  5. Which practice helps ensure a vendor's security controls remain effective between annual formal assessments?

    Answer: Establishing ongoing performance metrics and KPIs tied to security requirements in the SLA

    Security-specific SLA metrics and KPIs create contractual accountability for continuous control effectiveness rather than relying solely on periodic point-in-time reviews.

  6. A vendor claims full compliance with GDPR but operates exclusively in the US with no EU operations. What should you verify?

    Answer: Whether the vendor processes personal data of EU residents, which triggers GDPR applicability regardless of location

    GDPR applies based on where data subjects are located, not where the organization operates — any vendor processing EU residents' data must comply regardless of their physical location.

  7. What distinguishes a 'critical vendor' from a 'standard vendor' in a formal third-party risk program?

    Answer: Critical vendors have access to sensitive data or provide services whose failure would significantly disrupt operations

    Critical vendor designation is determined by factors such as access to sensitive or regulated data, operational dependency, and the potential business impact of a disruption or security failure.