Skip to content
All lessons
Objective 5.3Governance & Risk· 3 min read

Third-Party Risk

Explain the processes associated with third-party risk assessment and management

What you will learn

  • Explain why accountability stays with you however much work is outsourced.
  • Name the vendor lifecycle stages: assessment, selection, agreement, monitoring.
  • Tell the agreement types apart: SLA, MOU, MSA, NDA, BPA.
  • Know what rules of engagement mean and why they precede any penetration test.

The rule the whole objective rests on: work can be outsourced, accountability cannot. If your service provider leaks your customers' data, the customer complains about you and the regulator questions you. That is why vendor management is security work, not procurement.

The vendor lifecycle

  1. Assessment before contracting

    Security questionnaires, review of audit attestations, examination of their posture. What is not asked for here is hard to impose later.

  2. Selection

    Weighing capability, cost and risk — not cost alone.

  3. The agreement

    Where the obligations are written: service levels, incident notification, right to audit, and what happens to the data at the end.

  4. Ongoing monitoring

    A one-off assessment at signing is not enough: a supplier's posture changes, and so do its risks.

  5. Ending the relationship

    Retrieving the data, destroying their copies, revoking their access. The most neglected stage.

Agreement types

SLAService level agreement: sets the expected performance in measurable terms — uptime, response times — and the penalty for missing it.
MOUMemorandum of understanding: declares an intent to cooperate, and is usually not legally binding.
MSAMaster service agreement: the general terms governing all later work, so they are not renegotiated each time.
NDANon-disclosure agreement: protects the information exchanged.
BPABusiness partnership agreement: governs the relationship between two partners and each one's responsibilities.
Rules of engagementWhat is permitted and what is forbidden in a penetration test — scope, timing, techniques and contacts. Without it signed, the test is a crime.

An SLA is not a security guarantee

An SLA usually measures uptime and response time; it says nothing about encryption, incident notification or a right to audit unless those are written in. If the question asks about guaranteeing you are told of a breach within a set period, that is a specific contractual clause, not an automatic consequence of having an SLA.

Real-world example: what is not written cannot be demanded

A company uses a payroll processing provider. Two years in, the provider suffers a breach affecting its employees' data, and the company learns of it from the news eleven days later. Reviewing the contract, it finds no notification clause, no right to audit, and no obligation to destroy data at termination. The failure did not happen on the day of the breach but on the day of signature: no security assessment was done before contracting, and the agreement was written to cover price and service, not security. Accountability to the employees and the regulator stayed wholly with the company.

What matters on the exam

  • Accountability is not outsourced. Any option saying the supplier now answers to the regulator in your place is wrong.
  • SLA = measured performance. MOU = non-binding intent. MSA = umbrella terms for what follows. Read what the question is measuring.
  • Rules of engagement always precede a penetration test. Testing without documented authorisation is an offence, not a service.
  • Ongoing monitoring is part of the lifecycle. Assessment at signing alone is an incomplete answer in vendor-management questions.

Quick check

Answer in your head first, then reveal.

  1. A cloud provider leaks your customers' data. Who is accountable to the customer?Reveal the answer

    You. The customer contracted with you, not your provider. You may have contractual recourse against them, but accountability to the customer and the regulator remains yours.

  2. Which document sets 99.9% uptime and the penalty for missing it?Reveal the answer

    The service level agreement: its job is turning expectations into measurable numbers with a defined penalty.

  3. What are rules of engagement for, before a penetration test?Reveal the answer

    Defining scope, timing, permitted techniques and points of contact, and documenting the authorisation. Without them the tester's actions are indistinguishable from an attacker's — legally and technically.

  4. Why is assessing a vendor once at signing not enough?Reveal the answer

    Because their posture changes: they may be acquired, change subcontractors, lose a certification, or be breached. An old assessment describes a supplier that no longer exists.

Sign in to track your progress on this topic.

Your next step

Read the lesson, then mark it complete

Sources

Used to verify the facts. The writing is original to Passuit.