10: vendor risk managemrnt

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/24

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 2:15 AM on 8/1/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

25 Terms

1
New cards

Third-Party Vendor Risk

Potential security and operational challenges introduced by external entities collaborating with an organization.

2
New cards

Trusted Foundry Program

DoD program ensuring hardware microprocessors are authentic and securely manufactured without deviations.

3
New cards

Secondary Market Hardware Risk

Increased risk of acquiring counterfeit or tampered devices containing embedded malware or backdoors.

4
New cards

Managed Service Provider (MSP)

An external company hired to manage IT services or cloud infrastructure on behalf of an organization.

5
New cards

Supply Chain Attack

An attack targeting a weaker supplier to gain unauthorized access to a primary target.

6
New cards

Chip Washing

Repackaging a microchip with a cheaper component or one containing embedded malicious functionality.

7
New cards

SolarWinds Compromise (2021)

A major software supply chain attack distributing malware through compromised Orion software updates.

8
New cards

CHIPS Act of 2022

US federal statute providing funding to strengthen domestic semiconductor research and manufacturing.

9
New cards

Vendor Assessment

Process evaluating the security, reliability, and performance of third-party external entities.

10
New cards

Vendor Penetration Testing

Simulated cyberattacks against a supplier's systems to identify exploitable security vulnerabilities.

11
New cards

Right to Audit Clause

Contractual provision allowing an organization to inspect a vendor's internal processes and security compliance.

12
New cards

Internal Audit

A vendor's self-assessment evaluating its own operations and practices against required standards.

13
New cards

Independent Assessment

Evaluation performed by an unbiased third-party entity to validate vendor security standards.

14
New cards

Supply Chain Analysis

Deep-dive examination evaluating the security and integrity of every link in a vendor's supply chain.

15
New cards

Vendor Due Diligence

Rigorous vetting of a potential vendor's operational history, financial stability, and security practices.

16
New cards

Conflict of Interest

A situation where personal or financial ties bias the selection or evaluation of vendors.

17
New cards

Vendor Questionnaire

A standardized form asking potential vendors for detailed operational, security, and compliance information.

18
New cards

Rules of Engagement

Guidelines dictating acceptable communication protocols, data sharing, and boundaries with potential vendors.

19
New cards

Service Level Agreement (SLA)

Contract defining explicit performance metrics and standard parameters required from a service provider.

20
New cards

Memorandum of Agreement (MOA)

A formal document detailing specific roles, responsibilities, and obligations of collaborating parties.

21
New cards

Memorandum of Understanding (MOU)

A non-binding agreement expressing mutual intent and broad outlines for potential future collaboration.

22
New cards

Master Service Agreement (MSA)

A blanket agreement establishing general terms governing future specific work orders or transactions.

23
New cards

Statement of Work (SOW)

Document specifying exact deliverables, timelines, parameters, and milestones for a specific project.

24
New cards

Non-Disclosure Agreement (NDA)

Legal commitment ensuring confidential information shared during negotiations remains private and protected.

25
New cards

Business Partnership Agreement (BPA)

Contract establishing shared terms, profit sharing, and decision structures between entities pooling resources.