Third-Party Vendor Risks Flashcards

(26 cards)

1
Q

An attack that involves targeting a weaker link in the supply chain to gain access to a primary target

A

Supply Chain Attack

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

U.S federal statute that provides roughly $280 billion in new funding to boost research and manufacturing of semiconductor inside the U.S

A

Chips Act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Essential components in a wide range of products, from smartphones and cars to medical devices and defense systems

A

Semiconductors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Organizations that provide a range of technology services and support to businesses and other clients

A

Managed Service Providers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Process that organizations implement to evaluate the security, reliability, and performance of external entities

A

Vendor Assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Businesses or individuals that provide goods and services to an organization

A

Vendors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Individuals involved in the production and delivery of products or parts of products

A

Suppliers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Individuals hired by companies to manage IT services on behalf of an organization

A

Managed Service Providers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Simulated cyberattack against the supplier’s system to check for explitable vulnerabilities

A

Penetration Testing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Vendor’s self-assessment, where they evaluate their own practices against industry standards or organizational requirements

A

Internal Audit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Evaluation conducted by third-party entities that have no stake in the organization’s or vendor’s operations

A

Independent Assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Used to dive deep into a vendor’s entire supply chain and assess the security and reliability

A

Supply Chain Analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Process that organizations implement to evaluate the security, reliability, and performance of external entities

A

Vendor Assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Arise when personal or financial relationships could potentially cloud the judgment of individuals involved in vendor selection

A

Conflict of Interest

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Comprhensive documents that potential vendors fill out to offer insights into the operations, capabilities, and compliance

A

Vendor Questionaries

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Guidelines that dictate the terms of interaction between an organization and its potential vendors

A

Rules of Engagement

17
Q

Mechanism to ensure that the chosen vendor still alighns with the organizational needs and standards

18
Q

Involves a two-way communication channel where both the organization and the vendor share feedback

A

Feedback Loops

19
Q

A versatile tool that formally establishes a relationship between two parties

A

Basic Contract

20
Q

The standard of service a client can expect from a provider

A

Service-Level Agreement (SLA)

21
Q

Formal and outlines the specific responsibilities and roles of the involved parties

22
Q

Less binding and more of a declaration of mutual intent

23
Q

Blanket agreement that covers the general terms of engagement between parties across multiple transactions

A

Master Service Agreement (MSA)

24
Q

Used to specify details for a particular project

25
Commitment to privacy that ensures that any sensitive information shared during negotiations remains confidential between both parties
NDA
26
Document that goes a step beyond the basic contract when two entities decide to pool their resources for mutual benefit
BPA