Question 7 of 10Pro Only

How should an organization assess and manage security risks associated with third-party vendors? Describe the vendor risk management lifecycle and key controls.

Sample answer preview

Third-party vendor relationships extend an organization's risk profile beyond its direct control. Data breaches at vendors, service outages from suppliers, and security weaknesses in software dependencies can all impact the organization.

vendor risk managementthird-party riskdue diligenceSOC 2security questionnairesrisk tiering

Unlock the full answer

Get the complete model answer, key points, common pitfalls, and access to 9+ more Cybersecurity Analyst interview questions.

Upgrade to Pro

Starting at $19/month • Cancel anytime