Third party risk management UPDATED
ACTUAL Exam Questions and CORRECT
Answers
what is vendor risk management - CORRECT ANSWER - plan to identify and decrease
any uncertainness when hiring a third party vendor for it, products and service
What vendor risk revirews/assessments - CORRECT ANSWER - process of assessing and
identifying risk a vendor may have and wether they can mitigate,
what happens if the third party risks can not be mitigated to your companies standard -
CORRECT ANSWER - Risk have to be montiored and the impacts assessed, if risk
exceeds companies risk tolerance they will not continue with party
How do you conduct a vendor risk assessment? - CORRECT ANSWER - Ask questions
and risk metrics to assign risk value to each awnser
What do risk metrics grades help with - CORRECT ANSWER - helps identify, evaluate
and manage certain risk found
technical control examples - CORRECT ANSWER - username, passwords, protocols,
when do low risk vendors require assesments - CORRECT ANSWER - every 3 years
when do mid risk vendors require assessments - CORRECT ANSWER - 1 year to 6
months assessments
when should high risk vendors be assessed - CORRECT ANSWER - once a year