1/24
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Third-Party Vendor Risk
Potential security and operational challenges introduced by external entities collaborating with an organization.
Trusted Foundry Program
DoD program ensuring hardware microprocessors are authentic and securely manufactured without deviations.
Secondary Market Hardware Risk
Increased risk of acquiring counterfeit or tampered devices containing embedded malware or backdoors.
Managed Service Provider (MSP)
An external company hired to manage IT services or cloud infrastructure on behalf of an organization.
Supply Chain Attack
An attack targeting a weaker supplier to gain unauthorized access to a primary target.
Chip Washing
Repackaging a microchip with a cheaper component or one containing embedded malicious functionality.
SolarWinds Compromise (2021)
A major software supply chain attack distributing malware through compromised Orion software updates.
CHIPS Act of 2022
US federal statute providing funding to strengthen domestic semiconductor research and manufacturing.
Vendor Assessment
Process evaluating the security, reliability, and performance of third-party external entities.
Vendor Penetration Testing
Simulated cyberattacks against a supplier's systems to identify exploitable security vulnerabilities.
Right to Audit Clause
Contractual provision allowing an organization to inspect a vendor's internal processes and security compliance.
Internal Audit
A vendor's self-assessment evaluating its own operations and practices against required standards.
Independent Assessment
Evaluation performed by an unbiased third-party entity to validate vendor security standards.
Supply Chain Analysis
Deep-dive examination evaluating the security and integrity of every link in a vendor's supply chain.
Vendor Due Diligence
Rigorous vetting of a potential vendor's operational history, financial stability, and security practices.
Conflict of Interest
A situation where personal or financial ties bias the selection or evaluation of vendors.
Vendor Questionnaire
A standardized form asking potential vendors for detailed operational, security, and compliance information.
Rules of Engagement
Guidelines dictating acceptable communication protocols, data sharing, and boundaries with potential vendors.
Service Level Agreement (SLA)
Contract defining explicit performance metrics and standard parameters required from a service provider.
Memorandum of Agreement (MOA)
A formal document detailing specific roles, responsibilities, and obligations of collaborating parties.
Memorandum of Understanding (MOU)
A non-binding agreement expressing mutual intent and broad outlines for potential future collaboration.
Master Service Agreement (MSA)
A blanket agreement establishing general terms governing future specific work orders or transactions.
Statement of Work (SOW)
Document specifying exact deliverables, timelines, parameters, and milestones for a specific project.
Non-Disclosure Agreement (NDA)
Legal commitment ensuring confidential information shared during negotiations remains private and protected.
Business Partnership Agreement (BPA)
Contract establishing shared terms, profit sharing, and decision structures between entities pooling resources.