Tyscorpa Study resources Open the Academy

Third-Party Risk & Vendor Management

Vendor assessment, legal agreements, shared responsibility, and supply chain risk management.

SY0-701 Obj. 5.3 Security Program Management 20% of the exam

Vendor Assessment Process

  1. Vendor Selection: Evaluate security posture, certifications (SOC 2, ISO 27001), financial stability, and references
  2. Due Diligence: Security questionnaires (SIG, CAIQ), penetration test results, policy reviews
  3. Contract Negotiation: Include security requirements, SLAs, right-to-audit clauses
  4. Ongoing Monitoring: Periodic reassessments, continuous threat intelligence monitoring for vendor breaches
  5. Offboarding: Ensure all data returned/destroyed; revoke all access; review data retention

Legal Agreements

AgreementPurpose
NDA (Non-Disclosure Agreement)Protects confidential information shared with the vendor
SLA (Service Level Agreement)Defines performance standards and remedies for failure (uptime %, response time, support tiers)
MSA (Master Service Agreement)Overarching contract governing the relationship; references specific work orders/SOWs
SOW (Statement of Work)Specific deliverables, timeline, and pricing for a project or service
MOU (Memorandum of Understanding)Non-binding agreement outlining intent to work together; often used between government agencies
MOA (Memorandum of Agreement)More formal than MOU; legally binding in some jurisdictions
ISA (Interconnection Security Agreement)Documents technical and security requirements for a network interconnection between organizations
BPA (Business Partnership Agreement)Defines relationship between business partners including data handling responsibilities

Right to Audit

A contractual clause giving the customer the right to audit the vendor's security controls and practices. Essential for:

Vendor Assessment Methods

Supply Chain Risk Controls

Exam Tip: SLA = performance commitments. NDA = confidentiality. Right-to-audit = verify vendor security. SOC 2 Type II (audited over time) is more valuable than Type I (point-in-time). MSA is the umbrella; SOW is the specific project. ISA is specifically about network interconnections.
PreviousRisk Management NextAcronyms - Security Program Management

Test yourself on this

Reading is the easy half. The Academy has 1,360 exam-style questions, including performance-based ones, and it keeps pulling from whichever domain you keep getting wrong. Free to create an account.

Open the Academy