Security+
5.3Security Program Management and Oversight · 20% of exam

Explain the processes associated with third-party risk assessment and management

Vendor assessment, due diligence, questionnaires, and agreement types: SLA, MOU, MSA, NDA, BPA, SOW.

Reading time
18 min read
Flashcards
19 cards
Practice questions
8 questions · 2 PBQs

Third-party risk is where the supply chain vector from 2.2 becomes a management problem. The exam's focus is narrow and predictable: the agreement acronyms, and the right-to-audit clause.

Vendor assessment

How you evaluate a third party before and during the relationship:

Penetration testing

Testing the vendor's security directly, where the contract permits it.

Right-to-audit clause

A contractual term giving you the right to audit the vendor's security. It must be in the contract before you need it — you cannot demand access you did not negotiate.

Evidence of internal audits

The vendor's own audit results, which are useful but self-reported.

Independent assessments

Third-party audits such as SOC 2, carrying more weight because the assessor is not the vendor.

Supply chain analysis

Assessing the vendor's own suppliers — your risk extends through their dependencies, not just to them.

Vendor selection

Due diligence — investigating the vendor before engaging: financial stability, security posture, references, certifications.

Conflict of interest — identifying relationships that could compromise objectivity, such as an auditor with a financial stake in the vendor being audited.

The agreement types

The densest recall in the objective. Learn what each one is for.

AcronymFull namePurpose
SLAService Level AgreementDefines the performance expected — uptime, response times, and penalties for missing them
MOUMemorandum of UnderstandingStates shared intent. Generally not legally binding
MOAMemorandum of AgreementMore formal than an MOU, closer to binding, defines roles
MSAMaster Service AgreementThe umbrella contract; individual work is ordered under it
SOW / WOStatement of Work / Work OrderThe specific deliverables, timeline and scope under an MSA
NDANon-Disclosure AgreementProtects confidential information shared between parties
BPABusiness Partners AgreementGoverns a partnership — profit sharing, responsibilities, exit

Check yourself

Which agreement defines guaranteed uptime and the penalties if the vendor fails to meet it?

Check yourself

Two organisations sign a document expressing their intent to collaborate, with no binding obligations. Which agreement is this?

Ongoing management

Vendor monitoring — the relationship does not end at signing. Performance against the SLA, security posture and financial health all need periodic review.

Questionnaires — standardised security assessments sent to vendors, often annually.

Rules of engagement — the agreed scope and constraints for testing, defining what may be tested, when, and how. Essential before any penetration test of a third party.

Why this matters

A vendor compromise is your incident. The MSP and software-vendor routes in 2.2 both convert someone else's weakness into your breach, and the controls here are almost entirely contractual and procedural — you cannot patch a vendor.