Physical Validation Overview Flashcards

1
Q

Overview

A
  1. Physical Validation Objectives
  2. Risk-Based Approach
  3. Program Design and Scope
  4. When to Perform an Onsite

*Gold standard of due diligence.
-The difference between asking if the room is clean vs. checking to see if the room is clean.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Physical Validations:
Objectives

A

Who?
-Vendors that you need to spend time on.
-Your high risk vendors
-It takes time, yours and the vendors so make sure you’re spending resources correctly.

How?
-Virtual vis on sight.
Virtual with a collab tool

What?
-What are you going to be asking?
-What’s your scope?
-Does the vendor have their own data center or using a CSP like google, google cloud, AWS?

Where?
-Where are you going to be?
-Company headquarters?
-Manufacturing site?
-Data center?
Data center is often separate from the headquarters

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Physical Validation Risk-Based Approach

A

-Amount of Effort
-Criteria
-Cadence and Repeats

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Physical Validation Risk-Based Approach:
Amount of Effort

A

-Some organizations are extensive in their research
- Typically for Greg, he does 2 days and 1-2 people

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Physical Validation Risk-Based Approach:
Criteria

A

-When does a vendor require physical validation.
Systemically critical vendors on entry
Because of the value of physical validation, might be beneficial to do a physical validation rather than virtual questionnaire.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Physical Validation Risk-Based Approach:
Cadence

A

-How often are you going back to reevaluate?
Should be clearly defined
Risk based
Vendors that have been breached
High risk vendors with high significant findings annual or every other year

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Physical Validations:
Objectives:

A

Who?
How?
What?
Where?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Physical Validations:
Objectives:
Who?

A

Who
-Vendors that you need to spend time on.
-Your high risk vendors
-It takes time, yours and the vendors so make sure you’re spending resources correctly

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Physical Validations:
Objectives:
How?

A

How
-Virtual vs on sight.
-Virtual with a collab tool

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Physical Validations:
Objectives:
What?

A

What
-What are you going to be asking?
-What’s your scope?
-Does the vendor have their own data center or using a CSP like google, google cloud, AWS?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Physical Validations:
Objectives:
Where?

A

Where
-Where are you going to be going?
-Company headquarters? Manufacturing site? Data center?
Data center is often separate from the headquarters

How well did you know this?
1
Not at all
2
3
4
5
Perfectly