- Home
- All questions
- Question 84
CompTIA Security+ study material · question 84 of 611
An organisation's SaaS provider depends on a third-party payment processor that the organisation has never assessed. What is this exposure called?
Show the answer
Answer: A. Fourth-party risk
Fourth-party risk comes from a supplier's own suppliers, and is invisible unless the contract requires disclosure of dependencies.
Source: NIST SP 800-161 Rev. 1 (NIST) — SP 800-161 Rev. 1 › Supply Chain