5.3 Explain the processes associated with third-party risk assessment and management

Domain 5: Security Program Management and Oversight

Third-party risk covers how you evaluate, contract with, and monitor vendors and suppliers. Start with vendor assessment methods: penetration testing of vendor systems, right-to-audit clauses, internal audit evidence, independent assessments, and supply chain analysis. Know due diligence during vendor selection and the conflict-of-interest concerns that can bias it. The agreement types are the most testable content, so learn what each is for: an SLA sets measurable performance targets, an MOU or MOA records intent without strong enforceability, an MSA establishes an ongoing relationship with work orders or statements of work (SOW) defining specific engagements, an NDA protects confidential information, and a BPA governs partner responsibilities. Ongoing management matters too — vendor monitoring, questionnaires, and defined rules of engagement rather than a one-time check at signing. Candidates typically memorize the acronyms but miss the distinctions the exam probes: an SLA is enforceable and metric-driven while an MOU is not, and an SOW belongs under an MSA. Remember that outsourcing a function never outsources the accountability for its risk.

What you must know

common pitfall · Candidates treat vendor agreements as interchangeable, missing that an SLA carries enforceable metrics while an MOU signals intent and an SOW lives under an MSA.

Try a sample question

A company is selecting a SaaS provider to process customer payment data. The security team wants independent evidence that the provider's security controls operated effectively over the past year, but the provider does not permit customers to conduct their own audits. Which item should the team request?

  • A An independent SOC 2 Type II report covering the service
  • B The provider's completed self-assessment security questionnaire
  • C Results of the provider's most recent internal vulnerability scan
  • D A right-to-audit clause added to the master service agreement
Show answer & explanations
  • A correct ·Correct. A SOC 2 Type II report is an independent auditor's attestation covering both control design and operating effectiveness over a review period, providing exactly the third-party evidence needed when customer audits are not allowed.
  • B A self-assessment questionnaire is completed by the vendor about itself, so it lacks independence and cannot verify that controls actually operated effectively during the past year.
  • C A vulnerability scan is a point-in-time technical snapshot generated by the provider itself; it is neither independent nor a demonstration that controls operated effectively over a period.
  • D A right-to-audit clause only creates a contractual option to audit in the future; this provider refuses customer audits, and the clause itself supplies no evidence of control effectiveness.

sample item — the full bank runs 450+ questions at exam difficulty

Is objective 5.3 your weak spot?

The free readiness check finds your weakest objectives in 15 adaptive questions — then full access drills them until the gauge clears the cut line.

Check my readiness — free