What are the potential security and operational challenges from external collaborators?
These challenges arise from third-party vendor risks.
Define Threat Vectors.
Paths attackers use to gain access
Understanding threat vectors is crucial for identifying potential security risks.
Define Attack Surfaces.
Points where an unauthorized user can try to enter
Identifying attack surfaces helps in strengthening security measures.
List the various types of vulnerabilities.
Each type of vulnerability poses different risks to security.
What is involved in Vendor Assessments?
Vendor assessments are crucial for evaluating security before partnerships.
What is the importance of Vendor Selection and Monitoring?
Ensures that vendors continue to meet security and operational standards.
What are the types of Contracts and Agreements?
Each type serves a specific purpose in formalizing relationships and expectations.
What does Penetration Testing involve?
Simulated cyberattacks to identify vulnerabilities in supplier systems
Validates supplier’s cybersecurity practices and potential risks.
True or false: Supply Chain Attacks target the primary target directly.
FALSE
Supply chain attacks exploit vulnerabilities in suppliers or service providers to access more secure systems.
What is the CHIPS Act of 2022?
U.S. federal statute providing funding to boost semiconductor research and manufacturing
Aims to reduce reliance on foreign-made semiconductors and enhance security.
What are the considerations for selecting service providers?
These considerations are crucial for maintaining security in service provision.
What is the purpose of Vendor Questionnaires?
Provide insights into operations, capabilities, and compliance
Standardized criteria for fair and informed decision-making.
What is a Right-to-Audit Clause?
Contract provision allowing organizations to evaluate vendor’s internal processes for compliance
Ensures transparency and adherence to standards.
What does Internal Audits entail?
Vendor’s self-assessment of practices against industry or organizational requirements
Demonstrates commitment to security and quality.
What is a Service Level Agreement (SLA)?
Defines the standard of service a client can expect from a provider
Includes performance benchmarks and penalties for deviations.
What is the difference between a Memorandum of Agreement (MOA) and a Memorandum of Understanding (MOU)?
Both documents serve to clarify relationships but differ in binding nature.
What is a Business Partnership Agreement (BPA)?
Outlines partnership nature, profit-sharing, decision-making, and exit strategies
Defines ownership of intellectual property and revenue distribution.