Open cardosec

Case 1B1A87 · GRC · L3 Applied

Third-Party Vendor Risk

Practise as: Explain it · Deep dive
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Tier vendors by data access, system connectivity and business criticality; depth of review scales with tier.
  2. Evidence: SOC 2 Type II, ISO 27001 cert + SoA, pen test summaries, SIG or CAIQ questionnaires.
  3. Contracts: breach notification window, right to audit, data return/deletion, subprocessor approval, liability caps.
  4. Fourth-party risk: your vendor's subservice providers; check SOC 2 carve-outs and subprocessor lists.
  5. Monitor continuously, not just at onboarding: reassess annually, watch breach news, offboard and revoke access.

If the interviewer pushes back

  • How do you assess a critical vendor that refuses questionnaires and has no SOC 2?
  • What technical controls reduce vendor risk when contractual controls are weak?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.