『Your Vendor Just Got Breached. Here's How a CISSP Should Actually Think It Through.』のカバーアート

Your Vendor Just Got Breached. Here's How a CISSP Should Actually Think It Through.

Your Vendor Just Got Breached. Here's How a CISSP Should Actually Think It Through.

無料で聴く

ポッドキャストの詳細を見る

【Amazonプライム会員限定】今ならプレミアムプランが4か月 月額99円。

10月19日まで。※適用条件あり

Your organization's biggest data vendor just called. They think, but aren't fully sure yet, that some of your data went out the door in a breach on their side. In this episode, Professor Simon walks through how a CISSP should actually reason through that call, using a scenario from his own CISSP Blueprint book, and why the instinct to terminate the contract immediately usually isn't the strongest answer.

He covers where third-party risk sits in the current CISSP exam outline as Supply Chain Risk Management (Domain 1), the real tradeoffs between terminating a vendor relationship and staying engaged through your existing contractual rights, the difference between due diligence and due care, the four standard risk-response options (mitigation, avoidance, transfer, and acceptance), and a repeatable four-step framework for working through this kind of scenario question, on the exam or on the job.

In this episode you'll learn:

- Why the instinct to immediately terminate a vendor after a possible breach often isn't the strongest answer

- How CISSP scenario questions test proportionate judgment, not vocabulary

- Where third-party risk fits in the current exam outline as Supply Chain Risk Management (SCRM), Domain 1

- The difference between due diligence and due care, and why a program needs both

- The four standard risk-response options: mitigation, avoidance, transfer, and acceptance, and what each one actually does (and doesn't do)

- Why your own regulatory obligations don't pause while a vendor finishes investigating

- A repeatable four-step framework for working through this kind of scenario question


▶️ Companion YouTube Video: https://youtu.be/XF4PQOGv0i0

📝 Companion Blog Post: https://professorsimon.com/blog/cissp-vendor-breach-scenario-reasoning

📚 Companion Workbook (free, CISSP Blueprint exercise): https://professorsimon.com/free-guides

🎧 More Podcast Episodes: https://professorsimon.com/podcast

🧭 Figure out which cybersecurity path fits you: https://careervectors.com

🔗 Resources, blog & more: https://professorsimon.com/links

🌐 Website: https://professorsimon.com

💼 LinkedIn: https://www.linkedin.com/in/leonardsimon

📸 Instagram • X • TikTok: @profsimononline


If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit.

adbl_web_anon_alc_button_suppression_t1
まだレビューはありません