wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

9.1 Quiz 3rd Party InfoSec Risk Mgt Program Development

Total questions: 36

Worksheet time: 27mins

Name
Class
Date
1.

What makes a 3rd-Party InfoSec Risk Management Program a GOOD program? Select all that apply

a)

Plentiful and necessary steps to make sure it is thorough.

b)

Standardized

c)

Shortcuts are common to quicken the process

d)

Defensible

2.

Step 1 of building a TPISRM is to define (a)   .

3.

There are two MUST's when defining the purpose of a TPISRM Program. What are they?

a)

1. Must classify risk

2. Must assess severity

b)

All of these are MUST have's

c)

1. Must have a thorough plan with detailed steps.

2. Training

d)

1. Must have buy-in

2. Must document the purpose because it will be referenced often.

4.

The most common purpose of TPISRM is (a)   .

5.

In the context of TPISRM, what does defensibility mean?

a)

No risk is prevalent

b)

Do what you can to prevent bad things from happening

c)

Building correct firewalls and antivirus

d)

Assessing vendors

6.

Step 2 of building a GOOD TPISRM Program is (a)   .

7.

Policy is a good place to document the (a)   .

8.

In order for policy to be effective, ________ and ________ are mandatory.

a)

procedures, rules

b)

buy-in, support

c)

commitment, approval

d)

All of the above

9.

Third Party risk decisions are BEST made after the procurement process.

a)

True

b)

False

10.

Policy statements are (a)   . No exceptions (unless documented and approved).

11.

The 3rd step of the TPISRM Program is (a)   .

12.

At a minimum, these should be our requirements of the TPISRM Program: (select all that apply)

a)

Standardized

b)

Comprehensive

c)

Simple

d)

Accountability

e)

Objective

13.

Perfection is NOT a requirement, (a)   is.

14.

Step 4 of the TPISRM Program is (a)   .

15.

Step 4 of TPISRM is to define Process. What are the four steps that help us accomplish this?

a)

1. Inventory

2. Assess

3. Classify

4. Decide

b)

1. Classify

2. Inventory

3. Assess

4. Decide

c)

1. Inventory

2. Classify

3. Assess

4. Decide

d)

1. Assess

2. Decide

3. Classify

4. Inventory

16.

Who is in scope of the inventory process of TPISRM?

a)

Existing 3rd Party relationships.

b)

New 3rd Party relationships.

c)

Both existing and new 3rd Party relationships.

d)

Any 3rd Party relationship that is getting paid.

17.

Inherent risk is risk without accounting for (a)   .

18.

When we determine inherent risk, what are questions we should consider asking? (select all that apply)

a)

Do they provide mission critical services?

b)

Do they have physical or logical access to the organization?

c)

Are confidential records shared or accessed?

d)

How many confidential records are shared or accessed?

e)

None of the above

19.

Which controls are observable while assessing residual risk?

a)

Administrative

b)

Physical

c)

Internal Technical

d)

External Technical

20.

Which controls require a conversation when you are assessing residual risk?

a)

Administrative

b)

Physical

c)

Internal Technical

d)

External Technical

21.

What are different ways we can conduct risk assessments? (Select all that apply)

a)

Testing Results

b)

3rd-Party

c)

Audits

d)

Questionnaires

e)

All of the above

22.

In order to make solid risk decisions, __________ and __________ are required for objectivity.

a)

audits, reports

b)

scores, thresholds

c)

questions, answers

d)

conversations, tests

23.

What are the typical classifications when considering risk decisions?

a)

Accept

Mitigate

Tolerate

Avoid

b)

Allow

Mitigate

Transfer

Avoid

c)

Accept

Mitigate

Transfer

Ignore

d)

Accept

Mitigate

Transfer

Avoid

24.

Eliminating the ability for employees to work from home because of the added risk it subjects the organization is called...

a)

Risk Transfer

b)

Risk Acceptance

c)

Risk Avoidance

d)

Risk Mitigation

25.

Identifying a risk and logging it but then taking a conscious action not to invest money to mitigate the risk because it would cost more to fix than the actual risk itself is what type of risk?

a)

Risk Mitigation

b)

Risk Avoidance

c)

Risk Acceptance

d)

Risk Transfer

26.

When a doctor purchases malpractice insurance to cover any losses incurred from patient lawsuits, this is what kind of risk?

a)

Risk Acceptance

b)

Risk Avoidance

c)

Risk Mitigation

d)

Risk Transfer

27.

When a bank deploys cameras at all entrance points into the bank, this is considered what kind of risk?

a)

Risk Avoidance

b)

Risk Acceptance

c)

Risk Mitigation

d)

Risk Transfer

28.

When determining who does what, a ___________ model works best.

a)

responsible

b)

defined

c)

shared

d)

relevant

29.

Goals determine how (a)   we were.

30.

Goals should be __________ and ____________.

a)

smart, thorough

b)

simple, attainable

c)

complex, relevant

d)

None of the above

31.

Who is important to engage in the goal setting process of defining success? (check all that apply)

a)

Executive Management

b)

Security Analyst

c)

DevOps

d)

InfoSec Committee

32.

The _________ must meet the requirements AND comply with __________ AND enable the _____________.

a)

Purpose, Policy, Process

b)

Process, Policy, Purpose

c)

Policy, Purpose, Process

d)

Purpose, Policy, Process

33.

When executing the TPISRM Program, what does the Execution phase require? Select all that apply.

a)

Documentation like standards and procedures

b)

Socialization

c)

Training

d)

Ongoing communication with management

e)

None of the above

34.

Tracking everything that can be tracked is an important part of the Execution Phase. Which ones are examples of things that should be tracked. Select all that apply.

a)

Feedback

b)

Common remediations and risks

c)

Questions

d)

Length to complete the process

35.

The (a)   to the organization must ALWAYS be justified.

36.

When should TPISRM be implemented?

4 lines