Third-Party Risk Management Flashcards
7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Third-Party Risk Management flashcards as text
Which metric is MOST useful for measuring how quickly an organization identifies and responds to vendor-related security incidents?
Answer: Mean Time to Detect and Respond (MTTR/MTTD) for vendor incidents
MTTD and MTTR quantify detection and response speed, which are critical efficiency metrics for third-party incident management.
Which of the following is an example of residual risk in a vendor relationship?
Answer: The risk remaining after all agreed-upon controls and mitigations have been implemented
Residual risk is what remains after controls and mitigations are applied; it must be accepted, further mitigated, or transferred (e.g., via insurance).
A technology vendor notifies your organization of a ransomware attack affecting their systems that store your customer data. What should be your organization's FIRST response step?
Answer: Activate the vendor incident response playbook and notify your legal and security teams
Activating the incident response playbook ensures a structured, timely response involving the right stakeholders, including legal and security teams.
An inherent risk assessment of a vendor would evaluate risk:
Answer: Before any mitigating controls or safeguards are applied
Inherent risk represents the raw risk level associated with a vendor or activity before any controls are in place.
Which of the following BEST supports a risk-based approach to vendor due diligence?
Answer: Scaling the depth and frequency of assessments based on the vendor's risk tier and data access
A risk-based approach tailors due diligence intensity to each vendor's risk profile, ensuring efficient use of assessment resources.
What is the purpose of a vendor scorecard in ongoing third-party risk management?
Answer: To track and visualize key performance and risk indicators for a vendor over time
A vendor scorecard aggregates KPIs and KRIs into a dashboard that enables ongoing comparison of vendor performance and risk posture over time.
Which contractual provision requires a vendor to notify the client within a specified timeframe if a data breach involving the client's data occurs?
Answer: Data breach notification clause
A data breach notification clause establishes the vendor's obligation to promptly inform the client of any security incident affecting the client's data, often aligning with regulatory timeframes.