Case 1B1A87 · GRC · L3 Applied
Third-Party Vendor Risk
Practise as: Explain it · Deep dive
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Tier vendors by data access, system connectivity and business criticality; depth of review scales with tier.
- Evidence: SOC 2 Type II, ISO 27001 cert + SoA, pen test summaries, SIG or CAIQ questionnaires.
- Contracts: breach notification window, right to audit, data return/deletion, subprocessor approval, liability caps.
- Fourth-party risk: your vendor's subservice providers; check SOC 2 carve-outs and subprocessor lists.
- Monitor continuously, not just at onboarding: reassess annually, watch breach news, offboard and revoke access.
If the interviewer pushes back
- How do you assess a critical vendor that refuses questionnaires and has no SOC 2?
- What technical controls reduce vendor risk when contractual controls are weak?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.