Your security is only as strong as your weakest vendor. Organizations that outsource functions cannot outsource their accountability — they must manage the risks introduced by every party in their supply chain.
When you give a vendor access to your systems, data, or networks, you extend your attack surface. The vendor's security practices, their sub-processors, and even their software update pipeline become potential risk vectors for your organization. You cannot fully control a third party — but you can manage the risk they introduce.
| Tier | Characteristics | Due Diligence Level |
|---|---|---|
| Tier 1 (Critical) | Access to sensitive data; mission-critical services; financial partners | Full assessment: questionnaire, SOC 2, on-site if needed, annual review |
| Tier 2 (High) | Access to internal systems; moderate data access; business-impactful | Standard questionnaire, SOC 2 or equivalent, annual review |
| Tier 3 (Medium) | Limited data access; non-critical services | Abbreviated questionnaire, reference checks, biennial review |
| Tier 4 (Low) | No data access; commodity services | Basic screening only |
Onboarding: Due diligence before engagement — risk assessment, contractual security requirements, security questionnaire. Ongoing: Continuous monitoring — periodic reassessment, review SOC reports, track incidents, monitor news. Offboarding: Secure termination — data return/destruction, access revocation, certificate of destruction.
Contracts are TPRM's enforcement mechanism. Critical clauses: right to audit, breach notification requirements, security standards obligations (e.g., ISO 27001), sub-processor approval rights, data return/destruction, liability and indemnification, termination for cause.
ISO 27036 is a four-part standard dedicated entirely to information security in supplier relationships:
Establishes the framework for managing information security risks in supplier relationships throughout the relationship lifecycle.
Defines the requirements for acquirers and suppliers, including mutual security expectations and obligations at each relationship stage.
Addresses the specific risks of ICT supply chains — hardware, software, and services. Relevant to SolarWinds-style attacks on software update pipelines.
Applies the supplier relationship framework to cloud service providers. Covers shared responsibility, cloud-specific due diligence, and exit strategies.
The 2020 SolarWinds attack is the defining TPRM case study of the modern era. Nation-state attackers compromised SolarWinds' build pipeline to insert malicious code into Orion software updates. The attack teaches critical TPRM lessons:
The attackers did not break into victim organizations directly. They compromised a trusted software vendor and used the update mechanism — a path that bypassed traditional perimeter controls entirely.
Many affected organizations had SolarWinds questionnaires on file but never assessed the security of SolarWinds' own software development and update pipeline.
A Software Bill of Materials (SBOM) — a list of all components in software you run — enables faster incident response when a compromised component is discovered.
Annual assessments cannot detect a breach that occurs months after the assessment. Continuous monitoring of vendor security posture (threat intelligence feeds, dark web monitoring, breach disclosures) is increasingly essential.
SolarWinds Orion had highly privileged access across victim environments. The blast radius was amplified by excessive vendor permissions. Limit vendor access to the minimum required.
A comprehensive vendor security questionnaire covers these domains (based on SIG — Standardized Information Gathering questionnaire, and CSA CAIQ for cloud):
Does the vendor have a formal ISMS? ISO 27001 certified? CISO or equivalent? Annual risk assessment?
Is MFA required for privileged access? Least privilege enforced? Quarterly access reviews? PAM solution in use?
Where is data stored? Encryption at rest and in transit? Data classification policy? Data retention and destruction procedures?
Formal IR plan? Average time to notify customers of breaches? Recent incident history? Regulatory notifications?
BCP and DR plans tested? RTO/RPO for critical services? Geographic redundancy? Last BCP test date?
Which sub-processors are used? Are sub-processors subject to equivalent security requirements? Can customer approve changes?
Modern TPRM programs supplement periodic questionnaires with continuous monitoring tools and signals:
BitSight, SecurityScorecard, and similar platforms continuously measure a vendor's external security posture — unpatched vulnerabilities, exposed services, SSL certificate issues, malware indicators. Provide a real-time signal between formal assessments.
Track whether vendor credentials or data appear in underground markets or breach databases. Compromised vendor credentials can be weaponized to attack your environment.
Subscribe to intelligence sources (ISAC reports, FS-ISAC, H-ISAC, government advisories) that flag emerging threats affecting specific industries or vendor types.
Contracts must require vendors to notify you within a defined timeframe of security incidents that may affect your data. 24–72 hours is best practice; ensure this is contractually binding.
You are assessing CloudVault Inc., a new cloud storage provider that will process your company's confidential customer data. Complete each due diligence step as a GRC analyst — tier classification, questionnaire review, certification verification, and contract requirements.