Phase 11 · GRC: Governance, Risk & Compliance
TopicsThird-Party & Vendor Risk
Part of the Cybersecurity Roadmap.
Summary
Assessing and managing security risk introduced by external vendors and partners — a company's security posture is only as strong as its weakest connected third party, a lesson learned from many real breaches.
How to Learn This
- 1Draft a basic vendor security questionnaire covering data access and security controls.
- 2Learn why supply chain attacks through a trusted vendor are an increasingly common breach vector.
- 3Understand why ongoing vendor monitoring matters, not just a one-time onboarding assessment.
More topics in GRC: Governance, Risk & Compliance
Stuck on this topic? Ask an Insider
Get 1:1 guidance from people who've walked this exact path — free on the InsideEdge app.