Worksheets9.1 Quiz 3rd Party InfoSec Risk Mgt Program Development
Total questions: 36
Worksheet time: 27mins
What makes a 3rd-Party InfoSec Risk Management Program a GOOD program? Select all that apply
Plentiful and necessary steps to make sure it is thorough.
Standardized
Shortcuts are common to quicken the process
Defensible
Step 1 of building a TPISRM is to define (a) .
There are two MUST's when defining the purpose of a TPISRM Program. What are they?
1. Must classify risk
2. Must assess severity
All of these are MUST have's
1. Must have a thorough plan with detailed steps.
2. Training
1. Must have buy-in
2. Must document the purpose because it will be referenced often.
The most common purpose of TPISRM is (a) .
In the context of TPISRM, what does defensibility mean?
No risk is prevalent
Do what you can to prevent bad things from happening
Building correct firewalls and antivirus
Assessing vendors
Step 2 of building a GOOD TPISRM Program is (a) .
Policy is a good place to document the (a) .
In order for policy to be effective, ________ and ________ are mandatory.
procedures, rules
buy-in, support
commitment, approval
All of the above
Third Party risk decisions are BEST made after the procurement process.
True
False
Policy statements are (a) . No exceptions (unless documented and approved).
The 3rd step of the TPISRM Program is (a) .
At a minimum, these should be our requirements of the TPISRM Program: (select all that apply)
Standardized
Comprehensive
Simple
Accountability
Objective
Perfection is NOT a requirement, (a) is.
Step 4 of the TPISRM Program is (a) .
Step 4 of TPISRM is to define Process. What are the four steps that help us accomplish this?
1. Inventory
2. Assess
3. Classify
4. Decide
1. Classify
2. Inventory
3. Assess
4. Decide
1. Inventory
2. Classify
3. Assess
4. Decide
1. Assess
2. Decide
3. Classify
4. Inventory
Who is in scope of the inventory process of TPISRM?
Existing 3rd Party relationships.
New 3rd Party relationships.
Both existing and new 3rd Party relationships.
Any 3rd Party relationship that is getting paid.
Inherent risk is risk without accounting for (a) .
When we determine inherent risk, what are questions we should consider asking? (select all that apply)
Do they provide mission critical services?
Do they have physical or logical access to the organization?
Are confidential records shared or accessed?
How many confidential records are shared or accessed?
None of the above
Which controls are observable while assessing residual risk?
Administrative
Physical
Internal Technical
External Technical
Which controls require a conversation when you are assessing residual risk?
Administrative
Physical
Internal Technical
External Technical
What are different ways we can conduct risk assessments? (Select all that apply)
Testing Results
3rd-Party
Audits
Questionnaires
All of the above
In order to make solid risk decisions, __________ and __________ are required for objectivity.
audits, reports
scores, thresholds
questions, answers
conversations, tests
What are the typical classifications when considering risk decisions?
Accept
Mitigate
Tolerate
Avoid
Allow
Mitigate
Transfer
Avoid
Accept
Mitigate
Transfer
Ignore
Accept
Mitigate
Transfer
Avoid
Eliminating the ability for employees to work from home because of the added risk it subjects the organization is called...
Risk Transfer
Risk Acceptance
Risk Avoidance
Risk Mitigation
Identifying a risk and logging it but then taking a conscious action not to invest money to mitigate the risk because it would cost more to fix than the actual risk itself is what type of risk?
Risk Mitigation
Risk Avoidance
Risk Acceptance
Risk Transfer
When a doctor purchases malpractice insurance to cover any losses incurred from patient lawsuits, this is what kind of risk?
Risk Acceptance
Risk Avoidance
Risk Mitigation
Risk Transfer
When a bank deploys cameras at all entrance points into the bank, this is considered what kind of risk?
Risk Avoidance
Risk Acceptance
Risk Mitigation
Risk Transfer
When determining who does what, a ___________ model works best.
responsible
defined
shared
relevant
Goals determine how (a) we were.
Goals should be __________ and ____________.
smart, thorough
simple, attainable
complex, relevant
None of the above
Who is important to engage in the goal setting process of defining success? (check all that apply)
Executive Management
Security Analyst
DevOps
InfoSec Committee
The _________ must meet the requirements AND comply with __________ AND enable the _____________.
Purpose, Policy, Process
Process, Policy, Purpose
Policy, Purpose, Process
Purpose, Policy, Process
When executing the TPISRM Program, what does the Execution phase require? Select all that apply.
Documentation like standards and procedures
Socialization
Training
Ongoing communication with management
None of the above
Tracking everything that can be tracked is an important part of the Execution Phase. Which ones are examples of things that should be tracked. Select all that apply.
Feedback
Common remediations and risks
Questions
Length to complete the process
The (a) to the organization must ALWAYS be justified.
When should TPISRM be implemented?
