Exam objective

SY0-701 5.3: Third-Party Risk Management

Security+ Topic

Third-Party Risk Management for Security+

This Security+ topic covers vendor assessment evidence: penetration testing evidence, right-to-audit clauses, evidence of internal audits, independent assessments, and supply chain analysis; Vendor selection: due diligence and conflict of interest; Agreement types: SLA, MOA, MOU, MSA, work order, SOW, NDA, and BPA; Ongoing oversight: vendor monitoring, questionnaires, and rules of engagement.

Start first lesson

4 lessons in this topic

Common mistakes to avoid

1

Learners often treat vendor-provided internal audits and independent assessments as equal. The correction: internal audits are self-review evidence; independent assessments come from a separate party and usually provide stronger assurance.

2

Learners often confuse due diligence with vendor monitoring. The correction: due diligence is investigation before or during selection; monitoring is ongoing oversight after the relationship begins.

3

Learners often confuse SLA with SOW. The correction: SLA defines service performance targets; SOW defines project work, deliverables, and scope.

4

Learners often confuse questionnaires with independent evidence. The correction: a questionnaire is a structured request for information; evidence or assessment validates the answers.