Security Questionnaire
Reviewed responses covering governance, IAM, data security, vulnerability management, monitoring, incident response, and resilience.
PROJECT 04 / THIRD-PARTY RISK
A simulated third-party risk management assessment evaluating a cloud-based vendor's business criticality, data exposure, system connectivity, cybersecurity controls, due diligence evidence, identified gaps, residual risk, and required remediation.
01 / EXECUTIVE SUMMARY
Northstar Cloud Services is a fictional SaaS provider being evaluated before onboarding by a simulated organization.
The service would support an important business process, process confidential organizational information, maintain user accounts, and integrate with the organization's identity environment.
Because the vendor would handle sensitive information and support an important business function, the relationship is classified as Tier 1 / Critical and requires enhanced cybersecurity due diligence before approval.
The assessment identified several strong controls, including multifactor authentication, encryption, centralized logging, vulnerability scanning, and documented incident response procedures.
However, gaps were identified in privileged access governance, recovery testing evidence, subcontractor oversight, and incident notification requirements.
All vendor information, findings, evidence, and assessment results used in this project are simulated.
02 / VENDOR PROFILE
Third-party risk begins with understanding what the vendor does, what information it can access, how it connects to the organization, and what would happen if the service became unavailable or compromised.
Cloud-hosted SaaS platform supporting an important internal business process.
Confidential business information and employee-related information.
Federated organizational identities with role-based user access.
Internet-based SaaS access with approved application integrations.
Service disruption could negatively affect normal business operations.
Vendor relies on additional cloud and service providers to deliver portions of the service.
03 / INHERENT RISK
Inherent vendor risk considers the exposure created by the relationship before evaluating the effectiveness of the vendor's security controls.
04 / DUE DILIGENCE
Vendor claims should be supported by appropriate documentation and evidence before control effectiveness is accepted.
Reviewed responses covering governance, IAM, data security, vulnerability management, monitoring, incident response, and resilience.
Reviewed simulated independent assurance documentation describing security control design and operation.
Reviewed access control, vulnerability management, incident response, encryption, and backup policies.
Reviewed simulated architecture and data-flow documentation to understand system boundaries and integrations.
Reviewed backup, recovery, continuity, and restoration testing documentation.
Reviewed cybersecurity obligations, breach notification language, data handling, and subcontractor requirements.
05 / CONTROL ASSESSMENT
Representative controls were evaluated using questionnaire responses and simulated supporting evidence.
| Domain | Control | Evidence | Assessment | Risk |
|---|---|---|---|---|
| Governance | Documented information security program | Security policy and governance documentation | Effective | Low |
| IAM | MFA for workforce and administrative access | Authentication configuration and policy | Effective | Low |
| IAM | Privileged access reviews performed on a defined cadence | Incomplete review records | Partially Effective | High |
| Data Security | Encryption of data at rest and in transit | Encryption standard and configuration evidence | Effective | Low |
| Vulnerability Management | Recurring vulnerability scanning and remediation | Scan results and remediation process | Effective | Low |
| Monitoring | Centralized security logging and alerting | Logging architecture and monitoring procedures | Effective | Low |
| Incident Response | Documented incident response process | Incident response plan | Effective | Low |
| Incident Response | Contractual incident notification requirement | Contract language lacks defined notification timeframe | Deficient | High |
| Resilience | Periodic recovery testing | Limited restoration testing evidence | Partially Effective | Medium |
| Supply Chain | Security oversight of critical subprocessors | Incomplete evidence of recurring subprocessor review | Partially Effective | High |
06 / FINDINGS
| ID | Finding | Risk | Required Action | Status |
|---|---|---|---|---|
| TPR-001 | Evidence does not demonstrate consistent recurring privileged access reviews. | High | Establish quarterly privileged access certification and retain review evidence. | Open |
| TPR-002 | Contract does not establish a defined cybersecurity incident notification timeframe. | High | Add contractual incident notification requirements before production use. | Open |
| TPR-003 | Recovery testing evidence does not demonstrate regular full restoration validation. | Medium | Provide current recovery testing evidence and establish recurring restoration testing. | Open |
| TPR-004 | Evidence of recurring security review for critical subprocessors is incomplete. | High | Establish documented subprocessor security review and monitoring requirements. | Open |
07 / PRIORITY FINDING
The simulated vendor contract requires incident notification but does not define a specific notification timeframe.
Delayed notification could prevent the organization from quickly evaluating exposure, initiating incident response, meeting downstream obligations, or communicating with stakeholders.
Third-Party Incident Management
High
Vendor Management / Legal
Mitigate
The vendor may proceed through conditional approval, but the contractual notification requirement must be resolved before the service enters unrestricted production use.
08 / RESIDUAL RISK
Existing safeguards reduce the vendor's inherent exposure, but unresolved control gaps leave meaningful residual risk that requires continued treatment and monitoring.
09 / RISK DECISION
The vendor demonstrates multiple established cybersecurity safeguards, but the remaining findings require formal remediation and monitoring. Approval is therefore conditioned on documented treatment requirements rather than treating the assessment as a simple pass-or-fail exercise.
10 / CONTINUOUS MONITORING
Critical vendors require ongoing monitoring because security posture, services, subprocessors, business criticality, and threat exposure can change over time.
Perform recurring cybersecurity review based on the vendor's criticality and risk tier.
Track open remediation items, due dates, evidence, and risk acceptance decisions.
Reassess when services, data access, integrations, ownership, or hosting arrangements materially change.
Trigger additional review when significant vendor security incidents occur.
Obtain updated independent assurance reports and relevant security evidence.
Escalate overdue findings and material vendor risks to appropriate stakeholders.
11 / GRC TAKEAWAY
Determine assessment depth based on business criticality, data, access, and dependency.
Evaluate exposure created by the relationship before considering safeguards.
Validate vendor claims using documentation and supporting security evidence.
Identify effective, partially effective, and deficient vendor safeguards.
Determine remaining exposure after existing controls are considered.
Translate findings into remediation requirements, approval conditions, and ongoing monitoring.
PROJECT CONCLUSION
This project demonstrates how third-party cybersecurity risk can be evaluated through vendor tiering, inherent risk analysis, evidence-based due diligence, control assessment, finding management, residual risk analysis, conditional approval, and continuous monitoring.