Third-Party Risk Management

(1)

Third-party risk management covers how organizations assess and monitor the security of vendors, suppliers, and partners with access to their systems or data. Coverage of vendor security assessments, continuous monitoring, contractual and compliance requirements, supply chain compromise, and the programs that keep third-party risk from becoming a first-party breach.