Module 6 · Beginner · ⏱ 40 min · 🏆 +175 XP

Third-Party & Vendor Risk Management Basics

Your security is only as strong as your weakest vendor. Organizations that outsource functions cannot outsource their accountability — they must manage the risks introduced by every party in their supply chain.

TPRMDue Diligence Vendor TiersISO 27036 Supply Chain RiskSolarWinds

Learning Objectives

  • Explain why vendors introduce risk and how supply chain risk propagates.
  • Describe the three phases of vendor risk management: onboarding, ongoing, offboarding.
  • Apply a tiered risk classification to vendors based on data access and criticality.
  • Identify the key components of a vendor due diligence assessment.
  • Explain the SolarWinds attack and its TPRM lessons.
  • List the contractual security clauses required in vendor agreements.

Lecture

1 · Why Vendors Introduce Risk

When you give a vendor access to your systems, data, or networks, you extend your attack surface. The vendor's security practices, their sub-processors, and even their software update pipeline become potential risk vectors for your organization. You cannot fully control a third party — but you can manage the risk they introduce.

2 · Vendor Risk Tiers

TierCharacteristicsDue Diligence Level
Tier 1 (Critical)Access to sensitive data; mission-critical services; financial partnersFull assessment: questionnaire, SOC 2, on-site if needed, annual review
Tier 2 (High)Access to internal systems; moderate data access; business-impactfulStandard questionnaire, SOC 2 or equivalent, annual review
Tier 3 (Medium)Limited data access; non-critical servicesAbbreviated questionnaire, reference checks, biennial review
Tier 4 (Low)No data access; commodity servicesBasic screening only

3 · The Three Phases of TPRM

Onboarding: Due diligence before engagement — risk assessment, contractual security requirements, security questionnaire. Ongoing: Continuous monitoring — periodic reassessment, review SOC reports, track incidents, monitor news. Offboarding: Secure termination — data return/destruction, access revocation, certificate of destruction.

4 · Contractual Security Clauses

Contracts are TPRM's enforcement mechanism. Critical clauses: right to audit, breach notification requirements, security standards obligations (e.g., ISO 27001), sub-processor approval rights, data return/destruction, liability and indemnification, termination for cause.

Critical point: You cannot outsource your legal and regulatory obligations. If a vendor breaches your customers' data, you may still be liable under GDPR, HIPAA, or PCI-DSS.

Theory Deep Dive — Supply Chain Risk Management

🌐 ISO 27036 — Information Security for Supplier Relationships

ISO 27036 is a four-part standard dedicated entirely to information security in supplier relationships:

Part 1 — Overview and Concepts

Establishes the framework for managing information security risks in supplier relationships throughout the relationship lifecycle.

Part 2 — Requirements

Defines the requirements for acquirers and suppliers, including mutual security expectations and obligations at each relationship stage.

Part 3 — Guidelines for ICT Supply Chain Security

Addresses the specific risks of ICT supply chains — hardware, software, and services. Relevant to SolarWinds-style attacks on software update pipelines.

Part 4 — Guidelines for Security of Cloud Services

Applies the supplier relationship framework to cloud service providers. Covers shared responsibility, cloud-specific due diligence, and exit strategies.

☁️ The SolarWinds Attack — A TPRM Case Study

The 2020 SolarWinds attack is the defining TPRM case study of the modern era. Nation-state attackers compromised SolarWinds' build pipeline to insert malicious code into Orion software updates. The attack teaches critical TPRM lessons:

!
Attack Vector

The attackers did not break into victim organizations directly. They compromised a trusted software vendor and used the update mechanism — a path that bypassed traditional perimeter controls entirely.

1
TPRM Lesson: Tier 1 vendors need more than questionnaires

Many affected organizations had SolarWinds questionnaires on file but never assessed the security of SolarWinds' own software development and update pipeline.

2
TPRM Lesson: Software supply chain requires SBOM awareness

A Software Bill of Materials (SBOM) — a list of all components in software you run — enables faster incident response when a compromised component is discovered.

3
TPRM Lesson: Continuous monitoring over point-in-time assessments

Annual assessments cannot detect a breach that occurs months after the assessment. Continuous monitoring of vendor security posture (threat intelligence feeds, dark web monitoring, breach disclosures) is increasingly essential.

4
TPRM Lesson: Least privilege for vendor access

SolarWinds Orion had highly privileged access across victim environments. The blast radius was amplified by excessive vendor permissions. Limit vendor access to the minimum required.

📋 The Vendor Risk Questionnaire — Key Domains

A comprehensive vendor security questionnaire covers these domains (based on SIG — Standardized Information Gathering questionnaire, and CSA CAIQ for cloud):

Information Security Program

Does the vendor have a formal ISMS? ISO 27001 certified? CISO or equivalent? Annual risk assessment?

Access Control

Is MFA required for privileged access? Least privilege enforced? Quarterly access reviews? PAM solution in use?

Data Protection

Where is data stored? Encryption at rest and in transit? Data classification policy? Data retention and destruction procedures?

Incident Response

Formal IR plan? Average time to notify customers of breaches? Recent incident history? Regulatory notifications?

Business Continuity

BCP and DR plans tested? RTO/RPO for critical services? Geographic redundancy? Last BCP test date?

Sub-Processors / Fourth Parties

Which sub-processors are used? Are sub-processors subject to equivalent security requirements? Can customer approve changes?

📊 Continuous Monitoring — Moving Beyond Point-in-Time Assessment

Modern TPRM programs supplement periodic questionnaires with continuous monitoring tools and signals:

1
Security Rating Services

BitSight, SecurityScorecard, and similar platforms continuously measure a vendor's external security posture — unpatched vulnerabilities, exposed services, SSL certificate issues, malware indicators. Provide a real-time signal between formal assessments.

2
Dark Web Monitoring

Track whether vendor credentials or data appear in underground markets or breach databases. Compromised vendor credentials can be weaponized to attack your environment.

3
Threat Intelligence Feeds

Subscribe to intelligence sources (ISAC reports, FS-ISAC, H-ISAC, government advisories) that flag emerging threats affecting specific industries or vendor types.

4
Contractual Notification Requirements

Contracts must require vendors to notify you within a defined timeframe of security incidents that may affect your data. 24–72 hours is best practice; ensure this is contractually binding.

🧪 Lab — Third-Party Risk Due Diligence

You are assessing CloudVault Inc., a new cloud storage provider that will process your company's confidential customer data. Complete each due diligence step as a GRC analyst — tier classification, questionnaire review, certification verification, and contract requirements.

Scenario — Marketing Vendor Data Leak

Mission Quiz

Mission Complete

← Module 5 Next: Module 7 →