secplus

Dashboard / 5.0 Security Program Management and Oversight

5.3 Explain the processes associated with third-party risk assessment and management

Official exam objective outline (6 topics)
  • Vendor assessment
    • Penetration testing
    • Right-to-audit clause
    • Evidence of internal audits
    • Independent assessments
    • Supply chain analysis
  • Vendor selection
    • Due diligence
    • Conflict of interest
  • Agreement types
    • Service-level agreement (SLA)
    • Memorandum of agreement (MOA)
    • Memorandum of understanding (MOU)
    • Master service agreement (MSA)
    • Work order (WO)/statement of work (SOW)
    • Non-disclosure agreement (NDA)
    • Business partners agreement (BPA)
  • Vendor monitoring
  • Questionnaires
  • Rules of engagement

★ Starred in your notes: SLA · MSA · BPA · NDA.

Breakdown 1 — Why third parties matter

From class — third-party security concerns: not much control; check their policies. Supply-chain vectors (2.2) and MSP/vendor compromise reach you through the trust you extend.

Breakdown 2 — Vendor assessment (before and during)

ActivityWhat it is
Penetration testingRequire evidence the vendor tests its own systems (or allow you to)
Right-to-audit clauseContract term letting you (or your auditor) inspect the vendor's controls
Evidence of internal auditsVendor shares audit results
Independent assessmentsThird-party attestations: SOC 2 Type II, ISO 27001 certificate, PCI AOC
Supply chain analysisMap the vendor's own vendors — where do their risks come from?
QuestionnairesStandardized security questionnaires (SIG, CAIQ) the vendor completes
Vendor monitoringOngoing: re-assess yearly, watch their breaches, review SLA reports, risk-scoring services
Rules of engagementFor any testing you do against the vendor — scope, timing, contacts, what's off-limits

Breakdown 3 — Vendor selection

  • Due diligence — do your part before (class): financial stability, security posture, references, certifications, legal history.
  • Conflict of interest — the decision-maker (or the vendor) has a competing interest (auditor who also sells the product; employee with equity in the vendor). Disclose and separate.

Breakdown 4 — Agreement types (class: know SLA, MSA, BPA, NDA)

AgreementPurposeBinding?Class note
SLA — service-level agreementMeasurable service targets (uptime 99.999%, response time) and penaltiesYes"like cloud"
MSA — master service agreementUmbrella contract with general terms; individual work is added via SOWsYes"master service agreement"
WO / SOW — work order / statement of workSpecific deliverables, timeline, price for one project under the MSAYes
NDA — non-disclosure agreementProtects confidential information shared between partiesYes
BPA — business partners agreementDefines a partnership: responsibilities, profit sharing, decision rightsYes
MOU — memorandum of understandingStatement of intent/alignment; usually not bindingNo (typically)
MOA — memorandum of agreementMore detailed than an MOU; may be bindingSometimes
ISA — interconnection security agreementTechnical/security terms for connecting two networksYes(class: crossed out — "won't be on it")

Exam tip: "Uptime guarantee with credits" → SLA. "Framework contract, details in later documents" → MSA (+ SOW). "Two companies sharing profits on a joint product" → BPA. "Share a design under confidentiality" → NDA. "Two agencies agree to cooperate, no legal obligations" → MOU. "Contract lets us inspect their data center" → right-to-audit.

Quick self-check

  • MSA vs. SOW? (Umbrella terms vs. the specific job.)
  • Which agreement is typically non-binding? (MOU.)
  • What's the purpose of a right-to-audit clause?

Sources: 20260917_173307.jpg, 20260917_173312.jpg