Home » Uncategorized » 4th Masterclass by International TPRM Alliance

News/Events@HB

4th Masterclass by International TPRM Alliance

0%
3

4TPRMMasterclass

4th TPRM Masterclass

Please enter your full name, email address and location for certificate/score-generations! You will receive a certificate only if you score above 70%.

1 / 28

Category: 4TPRMMasterclass

1. For control A.5.19(Information security in supplier relationships), the presentation specifies what auditors look for as evidence. Which of the following correctly reflects that evidence requirement?

2 / 28

Category: 4TPRMMasterclass

How would you rate the overall experience of the event?

  • 2. Highly insightful and engaging
  • Informative and valuable
  • Average / satisfactory
  • Lengthy but useful
  • Too long and less engaging
  • Not relevant / could be improved

3 / 28

Category: 4TPRMMasterclass

3. The presentation identifies IP rights (A.5.32, Intellectual property rights) as particularly critical in agile outsourced engagements. What specific risk does it highlight that makes IP assignment more complex in this context?

4 / 28

Category: 4TPRMMasterclass

4. According to this presentation, how is A.8.30 (Outsourced Development) treated in the Statement of Applicability, and what determines its applicability?

5 / 28

Category: 4TPRMMasterclass

5. what does it mean for a control to be 'declared applicable in the SOA with no operational evidence'?

6 / 28

Category: 4TPRMMasterclass

6. The presentation explains that A.5.21(Managing information security in the information and communication technology (ICT) supply chain) extends beyond direct suppliers. What does it explicitly include in scope?

7 / 28

Category: 4TPRMMasterclass

7. The presentation distinguishes ISO 27002 from ISO 27001 in a specific and important way. Which statement accurately captures that distinction?

8 / 28

Category: 4TPRMMasterclass

8. Which clause of ISO 27001 explicitly requires that 'externally provided processes, products or services that are relevant to the ISMS are controlled'?

9 / 28

Category: 4TPRMMasterclass

9. A software company outsources the development of its mobile banking application to a third-party development firm. The firm delivers code bi-weekly via an agile sprint process. Under A.8.30 (Outsourced development
Control), which combination of actions does the presentation indicate the organisation must demonstrate?

10 / 28

Category: 4TPRMMasterclass

10. An organisation's A.5.23 process consists entirely of a SaaS vendor questionnaire completed at onboarding. The auditor notes a gap. Based on the presentation, which specific element of A.5.23(Information security for use of cloud services) is most clearly missing?

11 / 28

Category: 4TPRMMasterclass

11. What are the four lifecycle stages explicitly named in the A.5.23 requirement for cloud services?

12 / 28

Category: 4TPRMMasterclass

12. Under A.5.20(Addressing information security within supplier agreements), the presentation warns that a particular approach does NOT satisfy the 'established and agreed' requirement. Which approach is explicitly flagged as insufficient for high-risk suppliers?

13 / 28

Category: 4TPRMMasterclass

13. According to this presentation, when an organisation excludes a requirement from Clauses 4–10 of ISO 27001, how is this treated?

14 / 28

Category: 4TPRMMasterclass

14. According to this presentation, what percentage of significant data breaches involve a third party?

15 / 28

Category: 4TPRMMasterclass

15. In the TPRM operating model shown in this presentation, the 'Assess' step maps to specific ISO 27001 requirements and ISO 27002 implementation guidance. Which combination correctly describes both?

16 / 28

Category: 4TPRMMasterclass

Which topics would you like to see covered in future roundtables or masterclasses?
e.g.,

  • 16. Third-Party Cyber Risk & Continuous Monitoring
  • AI Risk in Vendor Ecosystems
  • Cloud & SaaS Risk Management
  • Regulatory Compliance (e.g., outsourcing, data protection)
  • Fourth-Party / Concentration Risk
  • Incident & Breach Management involving vendors
  • Other (please specify): __________

17 / 28

Category: 4TPRMMasterclass

17. An organisation uses a single standard NDA for all suppliers — from a one-person consultancy to a SaaS provider processing thousands of customer records. Under A.5.20 (Addressing information security within supplier agreements), why does the presentation indicate this approach creates a control gap for high-risk suppliers?

18 / 28

Category: 4TPRMMasterclass

18. A supplier relationship manager presents the following to an ISO 27001 auditor for A.5.19 (Information security in supplier relationships): a flat list of all active vendors with contract dates and the relevant account manager. The auditor raises a finding. What is the most accurate explanation for why this evidence is insufficient?

19 / 28

Category: 4TPRMMasterclass

19. The presentation states that the Statement of Applicability (SOA) must reflect all applicable supplier controls — not just the core four. How many primary supplier controls are listed in this presentation?

20 / 28

Category: 4TPRMMasterclass

20. According to the presentation, what is the TPRM operating model's five-step sequence?

21 / 28

Category: 4TPRMMasterclass

21. The presentation predicts that fourth-party assurance will become expected. What specific expansion of scope does it describe as the driver for this prediction?

22 / 28

Category: 4TPRMMasterclass

22. Please share your feedback on the event

  • What did you find most valuable?
  • What could be improved?
  • Any suggestions for future sessions?

23 / 28

Category: 4TPRMMasterclass

23. The presentation explains that ISO 27002 guidance items are not individually mandated and auditors must not raise nonconformities solely because an organisation chose a different implementation approach. However, there is an important limit to this principle. What is it?

24 / 28

Category: 4TPRMMasterclass

24. A.5.23 was introduced in ISO 27001:2022. What does this control cover?

25 / 28

Category: 4TPRMMasterclass

25. According to this presentation, what is the minimum set of security requirements the presentation recommends for ALL suppliers under A.5.20(Addressing information security within supplier agreements) implementation?

26 / 28

Category: 4TPRMMasterclass

26. According to the presentation, which of the following is a top nonconformity finding related to A.5.22 (Monitoring, review and change management of supplier services)?

27 / 28

Category: 4TPRMMasterclass

27. For A.8.30(Outsourced development), the presentation specifies three operative verbs that describe the organisation's obligations toward outsourced development. Which set is correct?

28 / 28

Category: 4TPRMMasterclass

28. For A.5.22(Monitoring, review and change management of supplier services), the presentation identifies three distinct obligations within the single control. What are they?

Your score is

0%

Exit