13 articles in the Third-Party & Supply Chain track of the Deep Trust Governance Series.
Every internal data flow in a mature enterprise has some form of governance: a data architecture record, an access control, a monitoring capability, a retention policy.
Vendor assurances are statements about what the vendor does. They appear in questionnaire responses, in sales presentations, in contract representations, and in certifica…
Vendor concentration risk is the risk that the organization's dependence on a small number of vendors for critical functions creates an exposure that the organization can…
The vendor completed the security questionnaire. Every question received a positive response. Multi-factor authentication: implemented. Encryption at rest: implemented.
The business continuity plan was comprehensive. It covered data center fires, network outages, hardware failures, and cyberattacks. It covered regional disasters with fai…
The acquisition closed on a Thursday. By the following Monday, the acquiring organization had inherited the acquired company's customer base, their revenue contracts, the…
Shadow IT is the technology adopted outside formal IT governance. Shadow procurement is the mechanism through which most shadow IT arrives: a business team identifies a t…
The contract specifies what the vendor is required to do. It defines data handling obligations, security standards, breach notification timelines, audit rights, and remed…
The annual vendor review is scheduled, conducted, documented, and closed. The vendor completes the updated questionnaire. The questionnaire is scored.
Procurement manages vendor relationships through the lens of commercial risk: price, delivery, contract terms, supplier financial stability, and performance against servi…
The argument for continuous vendor monitoring used to be a preference. Organizations with mature TPRM programs invested in ongoing monitoring because it was better practi…
The threat model covered the obvious vectors. Direct attacks on internet-facing systems. Phishing campaigns targeting employees. Credential theft and lateral movement.
This is not a rhetorical question. It is a governance question that most organizations cannot answer completely, and the completeness of the answer is a direct indicator…