Solutions

Vendor Risk Management: A Complete Platform

Map, assess and steer your vendor risk with campaigns, a security score and a centralised risk register.

TL;DR

Vendor risk management means identifying the third parties whose failure would affect your operations, assessing their security level in proportion to that criticality, then tracking the identified risks to closure. CISAPP connects vendors, internal activities, assessments and the risk register in one repository.

What is vendor risk management?

Vendor risk management means identifying the third parties whose failure would affect your operations, assessing their level of control in proportion to that criticality, then tracking the identified risks to closure. It is not a questionnaire sent once a year: it is a state to maintain, not a file to assemble.

How to prioritise assessment effort

Vendor criticality levels and the assessment depth expected
CriticalityTypical situationAssessment depthReassessment
CriticalSupports an essential activity, no quick alternativeFull questionnaire, evidence, audit or certificationAnnual and on events
HighAccess to sensitive dataTargeted questionnaire, certifications, external scanAnnual
ModerateLimited access, substitutable activityShort questionnaire, external scanEvery 2 years
LowNo access to systems or dataMinimal documentary checkAt contract review

How CISAPP keeps this view current

The risk register is shared between internal compliance and third parties: every risk points to the vendor concerned, the assessment that surfaced it and the remediation plan in progress. Dependency mapping links each third party to the activities it supports, which makes criticality defensible rather than declarative.

See also the vendor security score, the TPRM SaaS platform and the vendor cyber due diligence guide.

FAQ

It is the discipline of identifying the third parties whose failure — outage, compromise, non-compliance — would affect your organisation, assessing their level of control in proportion to that criticality, and tracking residual risks in a register until they are treated.

Sources

  1. ISO/IEC 27001:2022, controls A.5.19 to A.5.23 — supplier relationships — ISO, 2022-10-25

Ready to take control of your third-party risk?

I'm a company

We'll get back to you within 24 hours

I'm a vendor

Immediate onboarding

Create a free account