Question

Difficulty: EasyThird-Party Risk Management and Supply Chain Oversight

An organization has officially terminated its contract with a third-party software development vendor. To minimize third-party security risk immediately following the end of the contractual relationship, which of the following operational tasks should the security administrator complete first?

  1. Revoke all vendor user accounts, API keys, and remote access credentialsAnswer
  2. B
    Request an updated SOC 2 Type II audit report from the vendor
  3. C
    Draft a new Memorandum of Understanding to govern future engagements
  4. D
    Initiate an external vulnerability scan against the vendor's public infrastructure

Answer

Revoke all vendor user accounts, API keys, and remote access credentials
When ending a contract with a third party, prompt revocation of all user accounts, federated identities, API tokens, and remote access permissions is the most critical first step. This ensures former vendor employees cannot retain access to sensitive corporate resources or data.

Step-by-Step Solution

1
Identify the offboarding lifecycle phase
Recognize that the vendor relationship has officially terminated.
Offboarding requires immediate removal of third-party privileges to protect organizational assets.
2
Prioritize immediate risk reduction actions
Disabling access prevents external personnel from accessing internal systems or data.
Active vendor credentials post-termination create significant unauthorized access vectors.

Key Concept

Third-Party Offboarding and Access Lifecycle Management
Rate this question