Third Party Vendor Risk Flashcards

(22 cards)

1
Q

What is the Vendor Selection Process similar to?

A

It is similar to hiring a new employee – you can’t judge just by appearance.

供应商选择过程就像招聘员工,不能只看表面。

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is due diligence in vendor selection?

A

A rigorous background check that includes financials, history, reviews, and cultural fit.

尽职调查包括财务状况、运营历史、客户评价与文化契合度等多方面评估。

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the 4 components of due diligence?

A
  1. Evaluating financial stability
  2. Operational history
  3. Client testimonials
  4. On-the-ground cultural alignment

财务稳定性、运营历史、客户反馈、文化契合度。

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Why is it important to check for conflicts of interest when selecting a vendor?

A

To avoid biased decisions and ensure fair, transparent selection.

为防止选择偏向,确保公正与透明。

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a vendor questionnaire used for?

A

To assess a vendor’s operations, compliance, and technical capabilities.

供应商问卷用于了解其运营能力、合规性与技术实力。

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the purpose of ‘Rules of Engagement’ with vendors?

A

To define how both parties will communicate and share information securely.

指导双方如何合规、安全地互动与沟通。

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the 3 key elements in Rules of Engagement?

A
  1. Communication protocols
  2. Data sharing rules
  3. Negotiation boundaries

沟通协议、数据共享规则、谈判边界。

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is Vendor Monitoring?

A

The process of ensuring a vendor continues to meet standards over time.

持续监控供应商是否仍符合组织要求。

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are two tools used in Vendor Monitoring?

A
  1. Performance reviews
  2. Feedback loops

绩效评估和双向反馈机制。

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a Basic Contract?

A

A general contract defining duties, penalties, and terms.

基本合同:定义职责、违约处理与条款的通用协议。

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does an SLA define?

A

Service standards, performance metrics, and penalties.

SLA 服务级别协议:规定服务标准、性能指标及不达标的处理。

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What’s the difference between MOA and MOU?

A

MOA is formal with defined roles; MOU is informal and non-binding.

MOA 正式有约束,MOU 非正式表达意向。

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is an MSA used for?

A

Long-term partnerships; sets general terms across projects.

MSA 主服务协议:用于长期合作,规定通用条款。

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is an SOW?

A

A project-specific doc listing deliverables, timeline, and milestones.

SOW 工作说明书:细化交付物、时间表与里程碑。

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the purpose of an NDA?

A

To keep shared sensitive info confidential.

NDA 保密协议:保护合作中的敏感信息不被泄露。

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a BPA or JV Agreement?

A

For deep partnerships or joint ventures; defines roles, profit sharing, and IP rights.

BPA/JV 协议:用于深度合作或合资,明确分工、利润与知识产权归属。

17
Q

What is a Supply Chain Attack?

A

An attack that targets weak suppliers to reach the main target.

供应链攻击:通过薄弱供应商入侵主要目标。

18
Q

What is the CHIPS Act of 2022?

A

A U.S. law to boost domestic chip production and reduce foreign dependency.

2022芯片法案:提升美国芯片产能,减少对外国依赖,强化国家安全。

19
Q

What is Vendor Due Diligence?

A

A deep check of a vendor’s cybersecurity and supply chain practices.

供应商尽职调查:评估其网络安全与供应链管理。

20
Q

Why is Regular Monitoring & Audits important?

A

To detect suspicious activity and ensure ongoing compliance.

定期监控与审计:及时发现异常,确保持续合规。

21
Q

What does Education & Collaboration involve?

A

Sharing threat info and working with industry peers for stronger defense.

教育与协作:共享情报,行业联合防御。

22
Q

What are Contractual Safeguards?

A

Security requirements written into vendor contracts with legal consequences.

合同安全条款:合同中规定安全要求,违约可追责。