An organization is enhancing its third-party governance framework to address vendor oversight and supply chain security. Match each third-party risk management instrument on the left with its primary operational purpose on the right.
- Vendor Security Assessment Questionnaire (VSAQ)Evaluates self-reported security controls and operational practices during initial vendor onboarding
- Right-to-Audit Contractual ClauseEstablishes legal authority to inspect and verify the vendor's physical and technical security controls
- Hardware Bill of Materials (HBOM)Tracks physical component sourcing and sub-tier provenance to mitigate supply chain tampering
- Service Level Agreement (SLA)Defines measurable service performance metrics, uptime expectations, and remedies for non-compliance
Answer
Vendor Security Assessment Questionnaire matches with evaluating self-reported security controls; Right-to-Audit Clause matches with establishing legal authority to inspect controls; Hardware Bill of Materials matches with tracking physical component sourcing and sub-tier provenance; Service Level Agreement matches with defining measurable service performance metrics.
Each instrument fulfills a specific role in third-party risk management: Questionnaires assess self-reported baseline posture during onboarding, Right-to-Audit provisions grant verification permissions, HBOMs track physical component provenance against tampering, and SLAs define operational metrics and breach remedies.
Step-by-Step Solution
Key Concept
Third-Party Risk Management and Supply Chain Oversight Instruments