Solutions
Vendor Risk Management: A Complete Platform
Map, assess and steer your vendor risk with campaigns, a security score and a centralised risk register.
TL;DR
Vendor risk management means identifying the third parties whose failure would affect your operations, assessing their security level in proportion to that criticality, then tracking the identified risks to closure. CISAPP connects vendors, internal activities, assessments and the risk register in one repository.
What is vendor risk management?
Vendor risk management means identifying the third parties whose failure would affect your operations, assessing their level of control in proportion to that criticality, then tracking the identified risks to closure. It is not a questionnaire sent once a year: it is a state to maintain, not a file to assemble.
How to prioritise assessment effort
| Criticality | Typical situation | Assessment depth | Reassessment |
|---|---|---|---|
| Critical | Supports an essential activity, no quick alternative | Full questionnaire, evidence, audit or certification | Annual and on events |
| High | Access to sensitive data | Targeted questionnaire, certifications, external scan | Annual |
| Moderate | Limited access, substitutable activity | Short questionnaire, external scan | Every 2 years |
| Low | No access to systems or data | Minimal documentary check | At contract review |
How CISAPP keeps this view current
The risk register is shared between internal compliance and third parties: every risk points to the vendor concerned, the assessment that surfaced it and the remediation plan in progress. Dependency mapping links each third party to the activities it supports, which makes criticality defensible rather than declarative.
See also the vendor security score, the TPRM SaaS platform and the vendor cyber due diligence guide.
FAQ
It is the discipline of identifying the third parties whose failure — outage, compromise, non-compliance — would affect your organisation, assessing their level of control in proportion to that criticality, and tracking residual risks in a register until they are treated.
Sources
- ISO/IEC 27001:2022, controls A.5.19 to A.5.23 — supplier relationships — ISO, 2022-10-25
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours