CTPRP EXAM 1 COMPREHENSIVE EXAMS
SET TESTED QUESTIONS AND ACCURATE
ANSWERS GRADED A+
⩥ third party access to company data/systems.
Answer: it presents unique risks due to the inability to directly address
how they control access to those systems and data
⩥ TPRM.
Answer: a process for identifying and managing the risks created when
hiring a third party to provide goods and/or services. it's primary focus is
usually on data protection/privacy and IT security controls, but its scope
depends entirely on the nature of the services provided by the third party.
therefore, it may include operational issues such as business continuity
and disaster recovery, financial integrity, regulatory compliance, the
vendors own third party risk management practices
⩥ Requirements for third party oversight.
Answer: - relationships between organization and vendors has become
more complicated as vendors are being viewed as business partners
- risks associated with working with vendors have become complicated
as those vendors have been more popular targets for cyber attacks
- regulatory environment is more complex
- vendors are targeted by criminals
,⩥ governance model/structure to manage third party risk.
Answer: - define clear roles and responsibility
- risk management framework to focus approach
- "right-size" structure based on risk
⩥ first line of defense.
Answer: business who use the outsourced services. business unit
managers control the vendor relationship and may serve as primary
contact for gathering assessment due diligence and ensure remediation is
complete. they have ownership of risks the business unit will accept
⩥ second line of defense.
Answer: compromised of the groups within the company who provide
risk oversight (risk management, compliance, legal, etc). they establish
policies, procedures, controls for managing risk and provide
oversight/guidance for the first line
⩥ third line of defense.
Answer: internal/external audit provide validation for the risk and
control assessments established by the second line
⩥ policies.
, Answer: defined at enterprise level and include all relevant corporate
functions
⩥ standards.
Answer: corporate standards for risk tiers, rating, classifications and all
regulatory/industry guidelines to be followed
⩥ procedures.
Answer: "what" you're supposed to do to implement the policies
⩥ criteria for risk tiers will be used to establish.
Answer: - contract requirements
- level/type of assessment
- frequency of assessment
⩥ third party contract.
Answer: it defines entire relationship with vendor and establishes the
rights, roles and responsibilities, including ability to assess an require
remediation form vendor
⩥ jwhich areas of the company should be involved.
Answer: - business unit
- it
SET TESTED QUESTIONS AND ACCURATE
ANSWERS GRADED A+
⩥ third party access to company data/systems.
Answer: it presents unique risks due to the inability to directly address
how they control access to those systems and data
⩥ TPRM.
Answer: a process for identifying and managing the risks created when
hiring a third party to provide goods and/or services. it's primary focus is
usually on data protection/privacy and IT security controls, but its scope
depends entirely on the nature of the services provided by the third party.
therefore, it may include operational issues such as business continuity
and disaster recovery, financial integrity, regulatory compliance, the
vendors own third party risk management practices
⩥ Requirements for third party oversight.
Answer: - relationships between organization and vendors has become
more complicated as vendors are being viewed as business partners
- risks associated with working with vendors have become complicated
as those vendors have been more popular targets for cyber attacks
- regulatory environment is more complex
- vendors are targeted by criminals
,⩥ governance model/structure to manage third party risk.
Answer: - define clear roles and responsibility
- risk management framework to focus approach
- "right-size" structure based on risk
⩥ first line of defense.
Answer: business who use the outsourced services. business unit
managers control the vendor relationship and may serve as primary
contact for gathering assessment due diligence and ensure remediation is
complete. they have ownership of risks the business unit will accept
⩥ second line of defense.
Answer: compromised of the groups within the company who provide
risk oversight (risk management, compliance, legal, etc). they establish
policies, procedures, controls for managing risk and provide
oversight/guidance for the first line
⩥ third line of defense.
Answer: internal/external audit provide validation for the risk and
control assessments established by the second line
⩥ policies.
, Answer: defined at enterprise level and include all relevant corporate
functions
⩥ standards.
Answer: corporate standards for risk tiers, rating, classifications and all
regulatory/industry guidelines to be followed
⩥ procedures.
Answer: "what" you're supposed to do to implement the policies
⩥ criteria for risk tiers will be used to establish.
Answer: - contract requirements
- level/type of assessment
- frequency of assessment
⩥ third party contract.
Answer: it defines entire relationship with vendor and establishes the
rights, roles and responsibilities, including ability to assess an require
remediation form vendor
⩥ jwhich areas of the company should be involved.
Answer: - business unit
- it