Explain the processes associated with third-party risk assessment and management
Vendor assessment, due diligence, questionnaires, and agreement types: SLA, MOU, MSA, NDA, BPA, SOW.
- Reading time
- 18 min read
- Flashcards
- 19 cards
- Practice questions
- 8 questions · 2 PBQs
Third-party risk is where the supply chain vector from 2.2 becomes a management problem. The exam's focus is narrow and predictable: the agreement acronyms, and the right-to-audit clause.
Vendor assessment
How you evaluate a third party before and during the relationship:
Penetration testing
Testing the vendor's security directly, where the contract permits it.
Right-to-audit clause
A contractual term giving you the right to audit the vendor's security. It must be in the contract before you need it — you cannot demand access you did not negotiate.
Evidence of internal audits
The vendor's own audit results, which are useful but self-reported.
Independent assessments
Third-party audits such as SOC 2, carrying more weight because the assessor is not the vendor.
Supply chain analysis
Assessing the vendor's own suppliers — your risk extends through their dependencies, not just to them.
Vendor selection
Due diligence — investigating the vendor before engaging: financial stability, security posture, references, certifications.
Conflict of interest — identifying relationships that could compromise objectivity, such as an auditor with a financial stake in the vendor being audited.
The agreement types
The densest recall in the objective. Learn what each one is for.
| Acronym | Full name | Purpose |
|---|---|---|
| SLA | Service Level Agreement | Defines the performance expected — uptime, response times, and penalties for missing them |
| MOU | Memorandum of Understanding | States shared intent. Generally not legally binding |
| MOA | Memorandum of Agreement | More formal than an MOU, closer to binding, defines roles |
| MSA | Master Service Agreement | The umbrella contract; individual work is ordered under it |
| SOW / WO | Statement of Work / Work Order | The specific deliverables, timeline and scope under an MSA |
| NDA | Non-Disclosure Agreement | Protects confidential information shared between parties |
| BPA | Business Partners Agreement | Governs a partnership — profit sharing, responsibilities, exit |
Check yourself
Which agreement defines guaranteed uptime and the penalties if the vendor fails to meet it?
Check yourself
Two organisations sign a document expressing their intent to collaborate, with no binding obligations. Which agreement is this?
Ongoing management
Vendor monitoring — the relationship does not end at signing. Performance against the SLA, security posture and financial health all need periodic review.
Questionnaires — standardised security assessments sent to vendors, often annually.
Rules of engagement — the agreed scope and constraints for testing, defining what may be tested, when, and how. Essential before any penetration test of a third party.
Why this matters
A vendor compromise is your incident. The MSP and software-vendor routes in 2.2 both convert someone else's weakness into your breach, and the controls here are almost entirely contractual and procedural — you cannot patch a vendor.