CTPRP MAIN EXAMINATION SET 2026/2027
QUESTIONS AND SOLUTIONS RATED A+
✔✔onsite assessment - ✔✔- physical assessment of third party's risk controls
- check if controls are in place
- how well the vendor executes controls
✔✔kickoff meeting with third party determines: - ✔✔- contacts
- deliverables (documents and how/when you'll get them)
- timelines (key SMEs, risk control area to be reviewed in test procedures)
✔✔Vendor Risk Management Maturity model - ✔✔1. program governance
2. policies, standards, procedures
3. contract development, adherence & management
4. vendor risk assessment process
5. skills and expertise
6. communication & information sharing
7. tools, measurement & analysis
8. monitor and review
✔✔self assessment of controls include: - ✔✔- systems
- personnel (including subcontractors)
- processes
- policies (frequency of revision update)
- contractual compliance (controls specific to the contract)
✔✔recovery point objective (RPO) - ✔✔point in time in the past to which you will
recover
(at which point will you recover?)
✔✔recovery time objective (RTO) - ✔✔point in time in the future at which you will be up
and running again
(at which point will you be running again?)
✔✔business continuity - ✔✔the requirements to recover and resume technology
operations and requirements for critical business processes by end users performing
their respective job roles
✔✔disaster recovery - ✔✔process of resuming technical operations at a back-up site
while recovering operations at primary site
✔✔compliance requirements should be based on: - ✔✔- internal policies or objectives
- contractual requirements
- regulatory mandates
- industry-accepted best practices
, - external standards and frameworks
✔✔privacy management framework includes: - ✔✔- maintain personal data inventory
- maintain data privacy policies and notices
- maintain training and awareness program
- manage information security risk
- manage third party risk
- maintain procedures for inquires and complaints
- maintain data privacy breach management program
- monitor data handling practices and track external criteria
✔✔risk components to be evaluated in 'server security' - ✔✔- system types (windows,
unix, mainframe, etc)
- system operations
- system hardening
- security operations
third party - ✔✔entities or persons that work on behalf of the organization but are not its
employees, including consultants, contingent workers, clients, business partners,
service providers, subcontractors, vendors, suppliers, affiliates and any other person or
entity that accesses customer, company confidential/proprietary data and/or systems
that interact with that data
✔✔third party access to company data/systems - ✔✔it presents unique risks due to the
inability to directly address how they control access to those systems and data
✔✔TPRM - ✔✔a process for identifying and managing the risks created when hiring a
third party to provide goods and/or services. it's primary focus is usually on data
protection/privacy and IT security controls, but its scope depends entirely on the nature
of the services provided by the third party. therefore, it may include operational issues
such as business continuity and disaster recovery, financial integrity, regulatory
compliance, the vendors own third party risk management practices
✔✔Requirements for third party oversight - ✔✔- relationships between organization and
vendors has become more complicated as vendors are being viewed as business
partners
- risks associated with working with vendors have become complicated as those
vendors have been more popular targets for cyber attacks
- regulatory environment is more complex
- vendors are targeted by criminals
✔✔governance model/structure to manage third party risk - ✔✔- define clear roles and
responsibility
- risk management framework to focus approach
- "right-size" structure based on risk
QUESTIONS AND SOLUTIONS RATED A+
✔✔onsite assessment - ✔✔- physical assessment of third party's risk controls
- check if controls are in place
- how well the vendor executes controls
✔✔kickoff meeting with third party determines: - ✔✔- contacts
- deliverables (documents and how/when you'll get them)
- timelines (key SMEs, risk control area to be reviewed in test procedures)
✔✔Vendor Risk Management Maturity model - ✔✔1. program governance
2. policies, standards, procedures
3. contract development, adherence & management
4. vendor risk assessment process
5. skills and expertise
6. communication & information sharing
7. tools, measurement & analysis
8. monitor and review
✔✔self assessment of controls include: - ✔✔- systems
- personnel (including subcontractors)
- processes
- policies (frequency of revision update)
- contractual compliance (controls specific to the contract)
✔✔recovery point objective (RPO) - ✔✔point in time in the past to which you will
recover
(at which point will you recover?)
✔✔recovery time objective (RTO) - ✔✔point in time in the future at which you will be up
and running again
(at which point will you be running again?)
✔✔business continuity - ✔✔the requirements to recover and resume technology
operations and requirements for critical business processes by end users performing
their respective job roles
✔✔disaster recovery - ✔✔process of resuming technical operations at a back-up site
while recovering operations at primary site
✔✔compliance requirements should be based on: - ✔✔- internal policies or objectives
- contractual requirements
- regulatory mandates
- industry-accepted best practices
, - external standards and frameworks
✔✔privacy management framework includes: - ✔✔- maintain personal data inventory
- maintain data privacy policies and notices
- maintain training and awareness program
- manage information security risk
- manage third party risk
- maintain procedures for inquires and complaints
- maintain data privacy breach management program
- monitor data handling practices and track external criteria
✔✔risk components to be evaluated in 'server security' - ✔✔- system types (windows,
unix, mainframe, etc)
- system operations
- system hardening
- security operations
third party - ✔✔entities or persons that work on behalf of the organization but are not its
employees, including consultants, contingent workers, clients, business partners,
service providers, subcontractors, vendors, suppliers, affiliates and any other person or
entity that accesses customer, company confidential/proprietary data and/or systems
that interact with that data
✔✔third party access to company data/systems - ✔✔it presents unique risks due to the
inability to directly address how they control access to those systems and data
✔✔TPRM - ✔✔a process for identifying and managing the risks created when hiring a
third party to provide goods and/or services. it's primary focus is usually on data
protection/privacy and IT security controls, but its scope depends entirely on the nature
of the services provided by the third party. therefore, it may include operational issues
such as business continuity and disaster recovery, financial integrity, regulatory
compliance, the vendors own third party risk management practices
✔✔Requirements for third party oversight - ✔✔- relationships between organization and
vendors has become more complicated as vendors are being viewed as business
partners
- risks associated with working with vendors have become complicated as those
vendors have been more popular targets for cyber attacks
- regulatory environment is more complex
- vendors are targeted by criminals
✔✔governance model/structure to manage third party risk - ✔✔- define clear roles and
responsibility
- risk management framework to focus approach
- "right-size" structure based on risk