Third-Party Risk Management
So far, we’ve learned about IT risk management and the different methods to perform a risk assessment and response, as well as monitoring. In this chapter, we will dive deep into third-party risk management (TPRM), how to assess downstream third parties (vendors) and support businesses for upstream third parties (customers), and how to manage emerging risks. We will also look at how to manage issues, findings, and exceptions that may impact the business operations of an organization.
This chapter aims to help you learn about the concepts of TPRM and how to perform an effective third-party risk evaluation. We will also learn about issues, findings, and exceptions and how to manage them effectively.
In this chapter, we will cover the following topics:
- The need for TPRM
- Managing third-party risks
- Upstream and downstream third parties
- Responding to anomalies
With that, let’s dive into the first section: The need...