CompTIA Security+ SY0-701 · Free study guide
Objective 5.3 — Assess and manage third-party security risk
Third-party risk begins before selection and continues through termination. A vendor can introduce software, infrastructure, identity, data, personnel, and concentration dependencies. Contract language helps allocate responsibilities but does not replace verification.
Due diligence should be proportional to access and impact. Review service design, data flows, ownership, security program, incident history, continuity, subcontractors, location, financial viability, and exit options. Evidence may include questionnaires, internal audit results, independent assessments, certifications, penetration-test summaries, and supply-chain analysis. Confirm scope, date, exceptions, and relevance rather than accepting a logo.
Conflicts of interest can undermine selection or assessment. Separate commercial incentives from risk approval and disclose relationships.
Agreements serve different purposes
An SLA defines measurable service commitments. An MSA establishes reusable commercial and legal terms; a statement of work or work order defines a specific engagement. An NDA protects confidential information. MOAs and MOUs document shared responsibilities or intent, often between organizations. A business partners agreement governs an ongoing partnership. Choose the document that fits the need rather than treating every agreement as interchangeable.
Security terms may address control responsibilities, data use, location, breach notification, evidence, subcontractors, retention, deletion, recovery, service levels, and termination assistance. A right-to-audit clause preserves assessment options, but practical scope, notice, access, cost, and remediation terms matter.
Monitor and exit
Vendor monitoring should track service, control, vulnerability, incident, organizational, and subcontractor changes. Reassess when scope or risk changes. Rules of engagement define authorization, targets, time, techniques, contacts, safety constraints, data handling, and reporting for a test. Without them, even well-intentioned testing can become unauthorized or disruptive.
At termination, remove accounts and connectivity, retrieve or verify deletion of data, rotate shared secrets, preserve required records, and confirm continuity. Concentration risk may remain when several services depend on one provider.
Decision rule: match evidence and contract depth to access and impact, monitor throughout the relationship, and plan a verifiable exit before onboarding.
Practice and apply this objective
A free ExamOps account includes guided hands-on labs plus 10 practice questions per day shared across live tracks, with a written explanation on every question. No card required.
Start practicing free