Integrating a Process Across the Business
The most important part of your program is ensuring a robust process is in place for your cybersecurity Vendor Risk Management program and that it has been shared across the broader organization. In addition to it being shared, it is important the broader organization is aware of what is expected from them when onboarding vendors. This may not be the easiest task to complete, but it is important that time is spent creating a process that guides the business through onboarding a vendor correctly. Ensuring success and enforcing the process to be followed will require support and enforcement from the executive leadership team.
Earlier in the chapter, we reviewed the roles and responsibilities of everyone who may be involved with your Vendor Risk Management program. Depending on how your organization manages vendors, whether it is each individual function or a centralized group like procurement, will determine how to best integrate the process...