Risk and Third-Party Management

Hard

Find each risk or third-party concept hidden in the grid.

12 terms · Choose how you want to study

New to the CompTIA Security+ exam? Read our how-to-pass guide →

Study modes

Terms in this set

Risk

The likelihood and impact of a threat exploiting a vulnerability against an asset.

Risk is the intersection of a threat, a vulnerability it can exploit, and an asset of value — informally, Likelihood × Impact. Quantitative analysis puts dollars on it: SLE (single loss expectancy) = asset value × exposure factor, and ALE (annualized loss expectancy) = SLE × ARO (annual rate of occurrence), which justifies control spending. Once measured, every risk is treated one of four ways: mitigate, transfer, avoid, or accept.

Assessment

A point-in-time review of controls, risks, or vulnerabilities to inform improvement.

An assessment is a point-in-time review that feeds the improvement cycle: a risk assessment identifies and prioritizes risks to inform treatment, while a vulnerability assessment enumerates technical weaknesses to inform remediation. Penetration tests go a step further than vulnerability scans by actually exploiting findings to prove real-world impact — assessment identifies, the pen test demonstrates.

Vendor

A third party providing goods or services — and a third-party risk that must be managed.

Every vendor is also a third-party risk: their breach can become your breach (as supply-chain attacks like SolarWinds showed). Vendor risk management tiers suppliers by data sensitivity and business criticality, then applies proportionate due diligence and contractual controls — the highest-risk vendors get the deepest scrutiny. SOC 2 Type II reports, security questionnaires, and right-to-audit clauses are standard due-diligence inputs.

Contract

The agreement that binds vendor security obligations — DPAs, BAAs, MSAs, NDAs.

Contracts are where third-party security obligations become enforceable — DPAs (data processing), BAAs (HIPAA business associates), MSAs (master services), and NDAs each bind a different aspect. Essential security clauses include right-to-audit, breach-notification timelines, and data return/destruction on termination. Negotiate these at contract time; leverage to add them evaporates once the vendor is entrenched.

SLA

Service Level Agreement — measurable commitments for performance, uptime, and incident response.

An SLA sets measurable, contractual commitments for a service — uptime, performance, and crucially for security, incident-response and breach-notification times. Common metrics include uptime percentage, MTTR, and notification windows. An SLA without penalties for missing it is merely aspirational; tying it to financial remedies (service credits) is what makes it enforceable leverage over a vendor.

Tabletop

A discussion-based exercise that walks responders through an incident scenario.

A tabletop is a discussion-based exercise where responders talk through a realistic incident scenario, testing the plan, roles, and decision-making without touching production. It’s the cheapest exercise type and surfaces gaps — unclear ownership, missing contacts, untested assumptions — while building the cross-team relationships that matter during a real incident. Run them at least annually; functional and full-scale exercises follow as the program matures.

Compliance

Conforming to laws, regulations, contractual terms, and internal policy.

Compliance means conforming to external mandates (laws, regulations, contracts like PCI DSS) and internal policy. The critical exam point: compliance is the floor, not the ceiling — an organization can pass every audit and still be insecure, because frameworks lag real threats. Continuous control monitoring lowers the cost and pain of point-in-time audits and keeps the gap between “compliant” and “secure” small.

Inherent

The level of risk before any controls are applied.

Inherent risk is the raw, gross risk an activity carries before any controls are applied — the worst case if nothing were done. Subtract the effect of controls and you get residual risk: inherent − controls = residual. Reporting both side by side makes the value of the security program visible to leadership, showing how much risk the controls actually remove.

Residual

The level of risk remaining after controls are applied.

Residual risk is what remains after controls are applied (inherent − controls = residual) — no control set reduces risk to zero. This leftover is the decision point for leadership: accept it, transfer it (insurance), or invest in further mitigation. Whatever the choice, accepted residual risk should be documented, time-bound, and assigned an owner who revisits it on schedule.

Mitigation

Reducing risk by applying controls — the most common risk response.

Mitigation reduces risk by applying controls and is the most common of the four risk responses. Controls degrade over time — rules go stale, exceptions accumulate, configs drift — so mitigation must be paired with continuous monitoring and periodic validation to stay effective. Defense-in-depth deliberately layers multiple, overlapping mitigations so that no single control failure exposes the asset.

Transfer

Shifting risk to a third party — typically via insurance or outsourcing.

Transfer shifts a risk’s financial impact to a third party, usually through cyber insurance or by outsourcing the risky function. The crucial caveat: you can transfer the monetary loss but never the accountability — reputational damage and regulatory responsibility stay with you. Cyber insurers increasingly require evidence of baseline controls (MFA, EDR, backups) before they’ll write or pay on a policy.

Acceptance

Choosing to live with a risk because mitigation costs more than the impact.

Acceptance is one of the four risk responses (alongside mitigate, transfer, and avoid), chosen when the cost or friction of treatment exceeds the expected loss. The key is that it’s a deliberate, documented decision — with a named risk owner, a rationale, and a review date — not a gap nobody noticed. Acceptance is legitimate; ignorance is not.