Third-Party Vendor Compliance Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Third-Party Vendor Compliance flashcards as text
Which document formally defines the security obligations a vendor must meet before handling your organization's data?
Answer: Data Processing Agreement
A Data Processing Agreement (DPA) specifically governs how a vendor processes personal or sensitive data and the security controls required.
A vendor's SOC 2 Type II report covers a 12-month period ending six months ago. What is the primary concern?
Answer: Controls may have changed since the report period ended
A gap between the report period and today means new vulnerabilities or control failures may exist that are not reflected in the report.
What is 'fourth-party risk' in the context of vendor compliance?
Answer: Risk from a vendor's subcontractors or suppliers
Fourth-party risk refers to the risk that your vendor's own vendors (subcontractors) introduce into your supply chain.
When should a Vendor Risk Assessment be updated beyond the standard annual cycle?
Answer: When the vendor announces a material change such as an acquisition or data breach
Material changes such as acquisitions, breaches, or major service changes can alter a vendor's risk profile and require immediate reassessment.
A vendor refuses to complete your security questionnaire, citing trade secrets. What is the best response?
Answer: Request an independent third-party attestation or audit report instead
Third-party attestations such as SOC 2 or ISO 27001 certificates can satisfy due diligence requirements without exposing the vendor's proprietary details.
Which regulatory framework specifically requires covered entities to have Business Associate Agreements with vendors that handle protected health information?
Answer: HIPAA
HIPAA mandates Business Associate Agreements (BAAs) with any vendor that creates, receives, maintains, or transmits protected health information on behalf of a covered entity.
What is the purpose of a vendor tiering or classification system in a third-party risk program?
Answer: To allocate due diligence effort proportionally based on risk level
Vendor tiering ensures that critical or high-risk vendors receive intensive scrutiny while low-risk vendors receive lighter-touch assessments, optimizing program resources.