Understanding Vendor Risk Management
First, let’s take a high-level look at all the sub-functions that should be addressed as part of Vendor Risk Management. The following diagram captures much of what the Vendor Risk Management function entails.
Figure 10.1: Sub-functions of the Vendor Risk Management function
As more and more vendors continue to become compromised, we need to push them to do better with their cybersecurity practices. And the unfortunate reality is, there doesn’t seem to be any light at the end of the tunnel; it is only going to get worse before it gets any better. To make this more challenging, organizations continue to onboard vendor after vendor, constantly increasing the size of vendor portfolios. Unless it is a requirement from a regulation standpoint or there is some form of certification required for your organization, there’s a high possibility Vendor Risk Management is not being considered for your organization. Today, we...