[{"data":1,"prerenderedAt":163},["ShallowReactive",2],{"section-links-solutions-en":3,"section-links-reglementation-en":36,"section-links-guides-en":65,"section-links-comparatifs-en":90,"glossary-en":103},[4,8,12,16,20,24,28,32],{"label":5,"to":6,"description":7},"DORA + ISO 27001","\u002Fen\u002Fsolutions\u002Fdora-iso27001-compliance-software","Run DORA and ISO 27001 in one platform: CTPP register, SoA, Annex A controls and unified audit exports.",{"label":9,"to":10,"description":11},"NIS2 vendors","\u002Fen\u002Fsolutions\u002Fnis2-vendor-compliance","Extend your NIS2 compliance to your vendor chain: assessment campaigns, supply chain mapping and regulator-ready exports.",{"label":13,"to":14,"description":15},"Supply chain","\u002Fen\u002Fsolutions\u002Fsupply-chain-cybersecurity","Map your supply chain, assess your vendors' cybersecurity and track remediation through to risk closure.",{"label":17,"to":18,"description":19},"Third-party GRC","\u002Fen\u002Fsolutions\u002Fthird-party-grc-platform","CISAPP brings governance, risk and compliance (GRC) together for your third-party ecosystem: regulatory frameworks, audits and risk register.",{"label":21,"to":22,"description":23},"TPRM SaaS","\u002Fen\u002Fsolutions\u002Ftprm-saas","CISAPP is a TPRM SaaS platform unifying assessment campaigns, scoring, dependency mapping and regulatory compliance.",{"label":25,"to":26,"description":27},"Vendor risk","\u002Fen\u002Fsolutions\u002Fvendor-risk-management","Map, assess and steer your vendor risk with campaigns, a security score and a centralised risk register.",{"label":29,"to":30,"description":31},"Questionnaires","\u002Fen\u002Fsolutions\u002Fvendor-security-questionnaire","Run preconfigured vendor security questionnaire campaigns (ISO 27001, NIS2, DORA, GDPR) and track responses in real time.",{"label":33,"to":34,"description":35},"SecOps score","\u002Fen\u002Fsolutions\u002Fvendor-security-score","Track a vendor security score computed automatically from external technical scans (DNS, TLS, exposure, headers, breach), with history and alerts.",[37,41,45,49,53,57,61],{"label":38,"to":39,"description":40},"AI Act","\u002Fen\u002Fregulations\u002Fai-act","Prepare your EU AI Act compliance: AI system register, FRIA and article-level mapping, connected to your risk management.",{"label":42,"to":43,"description":44},"DORA","\u002Fen\u002Fregulations\u002Fdora","Manage your critical third-party ICT provider (CTPP) register, TLPT testing, and ICT incidents in an audit-ready DORA framework.",{"label":46,"to":47,"description":48},"GDPR","\u002Fen\u002Fregulations\u002Fgdpr","Maintain your records of processing activities and DPIAs, and manage data breaches with a severity wizard and a 72-hour notification tracker.",{"label":50,"to":51,"description":52},"ISO 27001","\u002Fen\u002Fregulations\u002Fiso-27001","Manage your Statement of Applicability (SoA), Annex A controls and ISO 27001 audit evidence in a single platform.",{"label":54,"to":55,"description":56},"NIS2","\u002Fen\u002Fregulations\u002Fnis2","Manage your NIS2 obligations (Article 21 measures, significant incidents, supply chain) and prepare regulator-ready exports from one platform.",{"label":58,"to":59,"description":60},"Part-IS","\u002Fen\u002Fregulations\u002Fpart-is","EASA Part-IS compliance (Regulations (EU) 2023\u002F203 and 2022\u002F1645): aviation ISMS, PSOE levels, Present & Suitable self-assessment, evidence and audit questionnaire.",{"label":62,"to":63,"description":64},"TISAX","\u002Fen\u002Fregulations\u002Ftisax","Understand TISAX assessment levels (AL1 to AL3), the VDA ISA catalogue, label validity, and what an automotive supplier must prove to its customers.",[66,70,74,78,82,86],{"label":67,"to":68,"description":69},"Fourth-party risk","\u002Fen\u002Fresources\u002Ffourth-party-risk","Your vendors depend on subcontractors you've never assessed. How to identify and manage this often-invisible fourth-party risk.",{"label":71,"to":72,"description":73},"Questionnaire fatigue","\u002Fen\u002Fresources\u002Fsecurity-questionnaire-fatigue","Why security questionnaires overwhelm procurement, security teams, and vendors alike, and how to break the re-entry cycle without losing rigor.",{"label":75,"to":76,"description":77},"Supply chain attack","\u002Fen\u002Fresources\u002Fsupply-chain-cyberattack","How a cyberattack at a vendor spreads into your organization, why it's hard to anticipate, and how to structure your defense against it.",{"label":79,"to":80,"description":81},"Concentration & SPOF","\u002Fen\u002Fresources\u002Fvendor-concentration-risk-spof","How to identify single points of failure (SPOF) hidden in your vendor chain and map risk concentration before an incident reveals it for you.",{"label":83,"to":84,"description":85},"Due diligence","\u002Fen\u002Fresources\u002Fvendor-cyber-due-diligence","How to structure cyber due diligence before signing a vendor contract, what to ask, and how to avoid inheriting a third party's risk unknowingly.",{"label":87,"to":88,"description":89},"Incident playbook","\u002Fen\u002Fresources\u002Fvendor-security-incident-playbook","What to do in the first hours after a vendor discloses a security incident: a 5-step playbook to assess impact, contain, and document.",[91,95,99],{"label":92,"to":93,"description":94},"CISAPP vs spreadsheet","\u002Fen\u002Fcomparisons\u002Fcisapp-vs-spreadsheet-third-party-risk","How far a spreadsheet takes you in vendor risk management, and the point at which it costs more than a platform: a comparison on verifiable criteria.",{"label":96,"to":97,"description":98},"European alternatives","\u002Fen\u002Fcomparisons\u002Feuropean-alternatives-us-tprm-platforms","What choosing a European vendor changes for third-party risk management: applicable law, data transfers, sovereignty and GDPR compliance.",{"label":100,"to":101,"description":102},"TPRM selection criteria","\u002Fen\u002Fcomparisons\u002Ftprm-platform-selection-criteria","An evaluation grid for third-party risk platforms: regulatory coverage, assessment cycle, evidence, hosting, integrations and total cost of ownership.",[104,108,112,116,120,124,127,131,135,139,143,147,151,155,159],{"slug":105,"term":106,"definition":107},"concentration-risk","Concentration risk","Concentration risk is the exposure created by an organisation's dependency on a small number of vendors, technologies or geographies, such that a single failure affects several essential activities at once.",{"slug":109,"term":110,"definition":111},"digital-operational-resilience","Digital operational resilience","Digital operational resilience is, under the DORA regulation, a financial entity's ability to build, assure and review its operational integrity and reliability in the face of ICT disruptions, including those originating from its ICT third-party providers.",{"slug":113,"term":114,"definition":115},"dpa","DPA (Data Processing Agreement)","A DPA (Data Processing Agreement) is the contract required by Article 28 of the GDPR between a controller and its processor. It sets the subject matter, duration, nature and purpose of the processing, the categories of data and data subjects, and the obligations on security, confidentiality, assistance and return or deletion of data.",{"slug":117,"term":118,"definition":119},"ebios-rm","EBIOS Risk Manager","EBIOS Risk Manager is the digital risk assessment and treatment method published by ANSSI, the French cybersecurity agency. It builds risk scenarios from risk sources and their targeted objectives, giving explicit weight to the ecosystem — partners and suppliers — as an attack path.",{"slug":121,"term":122,"definition":123},"nis2-essential-entity","Essential entity (NIS2)","An essential entity is, under the NIS2 directive, an organisation operating in a sector of high criticality and above the size thresholds set by the directive. It is subject to proactive supervision, unlike an important entity, which is supervised after the fact.",{"slug":125,"term":67,"definition":126},"fourth-party-risk","Fourth-party risk is the risk an organisation carries because of its vendors' own subcontractors — entities it has no direct contract with, yet on which the security or availability of the service it buys depends.",{"slug":128,"term":129,"definition":130},"records-of-processing-activities","Records of processing activities (ROPA)","The records of processing activities (ROPA) are the document required by Article 30 of the GDPR listing, for each personal data processing activity, its purpose, the categories of data and data subjects, the recipients, transfers outside the EU, retention periods and security measures.",{"slug":132,"term":133,"definition":134},"sbom","SBOM (Software Bill of Materials)","An SBOM (Software Bill of Materials) is the structured inventory of the components that make up a piece of software — libraries, transitive dependencies, versions and licences — allowing an organisation to determine whether a product is affected by a published vulnerability.",{"slug":136,"term":137,"definition":138},"security-posture-score","Security posture score","A security posture score is a synthetic indicator aggregating a vendor's assessment results — questionnaire answers, certifications, evidence provided, known incidents — to allow comparison and prioritisation across third parties.",{"slug":140,"term":141,"definition":142},"security-questionnaire","Security questionnaire","A security questionnaire is a structured set of questions sent to a vendor to document its security, continuity and compliance practices, and to objectify the gap between those practices and the requirements of the organisation assessing it.",{"slug":144,"term":145,"definition":146},"sub-processor","Sub-processor","A sub-processor is, under Article 28 of the GDPR, a provider engaged by a processor to carry out all or part of a processing activity on behalf of the controller. Engaging one requires the controller's authorisation and the flow-down of the same contractual obligations.",{"slug":148,"term":149,"definition":150},"tprm","TPRM (Third Party Risk Management)","TPRM (Third Party Risk Management) is the discipline of identifying, assessing, treating and monitoring the risks an organisation carries because of its relationships with external suppliers, service providers and partners — chiefly cybersecurity, continuity, compliance and data protection risks.",{"slug":152,"term":153,"definition":154},"trust-center","Trust Center","A Trust Center is the space a vendor maintains to publish, permanently and up to date, the elements of its security posture: certifications, audit reports, data location, sub-processor list, policies and contractual commitments.",{"slug":156,"term":157,"definition":158},"vendor-due-diligence","Vendor due diligence","Vendor due diligence is the assessment carried out before contracting, and periodically thereafter, to verify that a third party's security, compliance and continuity posture matches the criticality of the service it delivers and of the data it accesses.",{"slug":160,"term":161,"definition":162},"vendor-spof","Vendor SPOF","A vendor SPOF (single point of failure) is a third party whose unavailability is enough to halt an essential activity, because no alternative can be activated within the interruption tolerance of that activity.",1791391129322]