Shared Assessments Certified Third-Party Risk Professional (CTPRP) CTPRP Question # 34 Topic 4 Discussion

Shared Assessments Certified Third-Party Risk Professional (CTPRP) CTPRP Question # 34 Topic 4 Discussion

CTPRP Exam Topic 4 Question 34 Discussion:
Question #: 34
Topic #: 4

Which statement is TRUE regarding defining vendor classification or risk tiering in a TPRM program?


A.

Vendor classification and risk tiers are based upon residual risk calculations


B.

Vendor classification and risk tiering should only be used for critical third party relationships


C.

Vendor classification and corresponding risk tiers utilize the same due diligence standards for controls evaluation based upon policy


D.

Vendor classification and risk tier is determined by calculating the inherent risk associated with outsourcing a specific product or service


Get Premium CTPRP Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.