Lab 02 — Perform a Third-Party Security Risk Assessment
Mission Information
Section titled “Mission Information”| Item | Details |
|---|---|
| Lab | Lab 02 — Perform a Third-Party Security Risk Assessment |
| Module | 01 — GRC Fundamentals |
| Difficulty | Intermediate |
| Estimated Time | 120–150 Minutes |
| Role | GRC Analyst / Third-Party Risk Analyst |
| Primary Deliverable | Third-Party Security Risk Assessment Report |
| Environment | Spreadsheet / GRC Workspace / Documentation Tool |
| Lab Type | Third-Party Risk Management |
Mission Scenario
Section titled “Mission Scenario”NorthStar Digital Services is considering purchasing a new SaaS platform called CloudCollab.
CloudCollab will be used by multiple business teams to manage customer projects, documents, collaboration, and workflow automation.
The proposed service will:
-
Be used by approximately 1,500 employees.
-
Process customer contact information.
-
Store internal confidential documents.
-
Integrate with Microsoft Entra ID.
-
Support SSO.
-
Receive user profile information.
-
Store application data in the cloud.
-
Use several subprocessors.
-
Support business-critical customer operations.
The business team wants the vendor approved quickly.
However, before a contract can be signed, NorthStar’s Third-Party Risk Management team requires a formal security assessment.
You have been assigned as the GRC / Third-Party Risk Analyst responsible for the assessment.
Your responsibility is to determine:
What risk does this vendor introduce?
What data will it process?
How critical is the service?
What controls does the vendor have?
What evidence supports those controls?
What gaps exist?
What residual risk remains?
Can the vendor be approved?
What conditions should apply?Mission Objectives
Section titled “Mission Objectives”By completing this lab, you will learn how to:
-
Perform vendor intake.
-
Identify the business owner.
-
Determine data sensitivity.
-
Determine business criticality.
-
Assess inherent third-party risk.
-
Assign a vendor risk tier.
-
Perform security due diligence.
-
Review a vendor security questionnaire.
-
Review SOC 2 assurance.
-
Review ISO/IEC 27001 certification.
-
Review penetration-testing evidence.
-
Evaluate IAM controls.
-
Evaluate data-protection controls.
-
Evaluate vulnerability management.
-
Evaluate incident response.
-
Evaluate business continuity.
-
Identify fourth-party dependencies.
-
Document vendor findings.
-
Calculate residual risk.
-
Recommend remediation.
-
Make an approval recommendation.
-
Build a professional Third-Party Risk Assessment Report.
Prerequisites
Section titled “Prerequisites”Before beginning this lab, you should understand:
-
Third-Party Risk Management.
-
Enterprise risk management.
-
Risk assessment methodology.
-
Control design.
-
Control testing.
-
Audit and assurance.
-
Compliance management.
Recommended lessons:
03 Enterprise Risk Management
04 Risk Assessment Methodology
07 Control Design & Implementation
08 Control Testing & Effectiveness
09 Audit & Assurance Fundamentals
10 Compliance Management
11 Third-Party Risk ManagementLab Architecture
Section titled “Lab Architecture”You will follow this workflow:
Vendor Request ↓Vendor Intake ↓Inherent Risk Assessment ↓Vendor Tiering ↓Security Questionnaire ↓Evidence Review ↓Control Assessment ↓Security Findings ↓Residual Risk ↓Remediation ↓Risk Decision ↓Approval / Rejection ↓Ongoing MonitoringPart 1 — Create the Vendor Intake Record
Section titled “Part 1 — Create the Vendor Intake Record”Create a worksheet or document named:
Vendor IntakeUse the following fields:
| Field | Value |
|---|---|
| Vendor Name | CloudCollab |
| Service | SaaS Collaboration Platform |
| Business Owner | Director of Customer Operations |
| Users | 1,500 |
| Hosting Model | SaaS |
| Identity Integration | Microsoft Entra ID / SSO |
| Business Criticality | High |
| Customer Data | Yes |
| Confidential Data | Yes |
| Personal Data | Yes |
| Payment Data | No |
| Production Access | No direct access to NorthStar infrastructure |
| External Integration | Yes |
| Subprocessors | Yes |
Part 2 — Understand the Business Use Case
Section titled “Part 2 — Understand the Business Use Case”Document why the vendor is required.
Example:
CloudCollab will provide centralized project collaboration, document management, customer workflow tracking, and internal team coordination.
Ask:
-
Which teams will use it?
-
What happens if it becomes unavailable?
-
What information will be stored?
-
How long will data remain?
-
Will customers depend on it?
-
Are alternative systems available?
Student Action
Section titled “Student Action”Write a short Business Impact Statement.
Example structure:
Loss of CloudCollab for an extended period could disrupt customer project coordination and internal business workflows, resulting in productivity loss, delayed customer services, and potential contractual impact.
Part 3 — Identify Data Types
Section titled “Part 3 — Identify Data Types”Create:
Vendor Data ClassificationConsider these categories:
| Data Type | Present? | Classification |
|---|---|---|
| Public Information | Yes | Public |
| Employee Names | Yes | Internal |
| Customer Contact Data | Yes | Confidential |
| Internal Documents | Yes | Confidential |
| Authentication Metadata | Yes | Confidential |
| Payment Card Data | No | — |
| Health Data | No | — |
| Credentials | No direct passwords expected | Restricted if present |
Student Action
Section titled “Student Action”Identify whether any additional data categories may be processed.
Part 4 — Map the Data Flow
Section titled “Part 4 — Map the Data Flow”Create a simple data flow:
NorthStar User ↓Microsoft Entra ID ↓SSO Authentication ↓CloudCollab ↓Vendor Cloud Environment ↓Database / Storage ↓Vendor SubprocessorsDocument:
-
Source of data.
-
Authentication flow.
-
Storage location.
-
Data-processing locations.
-
Subprocessor involvement.
-
Data return/deletion process.
Why This Matters
Section titled “Why This Matters”Third-party risk cannot be understood without knowing where data travels.
Part 5 — Perform Inherent Risk Assessment
Section titled “Part 5 — Perform Inherent Risk Assessment”Assess risk before considering vendor controls.
Use the following categories.
| Risk Factor | Score |
|---|---|
| Data Sensitivity | 1–5 |
| Business Criticality | 1–5 |
| User Population | 1–5 |
| System Integration | 1–5 |
| Regulatory Impact | 1–5 |
| Subprocessor Dependency | 1–5 |
For CloudCollab, use:
Data Sensitivity = 4
Business Criticality = 4
User Population = 4
System Integration = 3
Regulatory Impact = 3
Subprocessor Dependency = 4Part 6 — Calculate Inherent Vendor Risk
Section titled “Part 6 — Calculate Inherent Vendor Risk”Add the scores:
4 + 4 + 4 + 3 + 3 + 4 = 22Use this tiering model:
| Score | Tier |
|---|---|
| 6–10 | Tier 4 — Low |
| 11–16 | Tier 3 — Moderate |
| 17–21 | Tier 2 — High |
| 22–30 | Tier 1 — Critical |
CloudCollab score:
22Therefore:
Vendor Tier:Tier 1 — CriticalThis means enhanced due diligence is required.
Part 7 — Determine Assessment Requirements
Section titled “Part 7 — Determine Assessment Requirements”For a Tier 1 vendor, require:
-
Full security questionnaire.
-
SOC 2 Type II report.
-
ISO/IEC 27001 certificate.
-
Penetration-test summary.
-
Business continuity information.
-
Incident-response information.
-
Privacy documentation.
-
Subprocessor inventory.
-
Security findings review.
-
Contractual security review.
Create an assessment checklist.
Part 8 — Review the Vendor Security Questionnaire
Section titled “Part 8 — Review the Vendor Security Questionnaire”Assume CloudCollab provides the following responses.
| Domain | Vendor Response |
|---|---|
| Information Security Program | Yes |
| Security Policies | Yes |
| Dedicated Security Team | Yes |
| MFA for Workforce | Yes |
| MFA for Privileged Users | Partial |
| SSO Support | Yes |
| Encryption at Rest | Yes |
| Encryption in Transit | Yes |
| Vulnerability Scanning | Yes |
| Penetration Testing | Yes |
| SIEM / Security Monitoring | Yes |
| Incident Response Plan | Yes |
| Annual IR Testing | Yes |
| Business Continuity Plan | Yes |
| Annual DR Test | No |
| Vendor Risk Program | Yes |
| Security Awareness | Yes |
| Secure SDLC | Yes |
| Subprocessor Assessments | Yes |
Part 9 — Identify Questionnaire Concerns
Section titled “Part 9 — Identify Questionnaire Concerns”Immediately flag:
Concern 1:Privileged MFA only partially implemented.
Concern 2:No annual disaster recovery test.Do not yet determine final severity.
Evidence review comes next.
Part 10 — Review SOC 2 Type II
Section titled “Part 10 — Review SOC 2 Type II”Assume CloudCollab provides a SOC 2 Type II report.
Report details:
Report Type:SOC 2 Type II
Period:1 January – 31 December 2025
Criteria:SecurityAvailabilityConfidentiality
Service:CloudCollab SaaS Platform
Auditor Opinion:UnmodifiedPart 11 — SOC Report Exceptions
Section titled “Part 11 — SOC Report Exceptions”The report includes two exceptions.
Exception 1
Section titled “Exception 1”Four privileged administrator accounts were temporarily excluded from MFA during a system migration.
Vendor response:
Three accounts remediated.
One legacy administrative account remains without MFA.Exception 2
Section titled “Exception 2”Disaster recovery test was not performed during the assessment period.
Vendor response:
Test planned for Q4 2026.These exceptions directly support your questionnaire concerns.
Part 12 — Review Complementary User Entity Controls
Section titled “Part 12 — Review Complementary User Entity Controls”The SOC report lists:
Customer Responsibilities:
Enable SSO.
Configure MFA through corporate identity provider.
Periodically review user access.
Remove access for terminated employees.
Secure integration credentials.Student Action
Section titled “Student Action”Document these as NorthStar Responsibilities.
They must eventually become internal controls.
Part 13 — Review ISO/IEC 27001 Certification
Section titled “Part 13 — Review ISO/IEC 27001 Certification”CloudCollab provides:
Certification:ISO/IEC 27001
Status:Valid
Scope:CloudCollab SaaS platform, supporting production operations, security, engineering, and customer support.
Expiration:30 June 2027Assessment conclusion:
Certification appears relevant and in scope.However:
ISO certification does not eliminate the need to evaluate specific control weaknesses.
Part 14 — Review Penetration-Test Evidence
Section titled “Part 14 — Review Penetration-Test Evidence”CloudCollab provides an independent penetration-test summary.
Details:
Testing Date:March 2025
Scope:External web applicationAPIAuthentication
Critical Findings:0
High Findings:2
Medium Findings:6Status:
Both High findings:Remediated
Retest:CompletedHowever, the assessment is now more than a year old.
Student Action
Section titled “Student Action”Determine whether the age of the penetration test should create a finding.
Recommended conclusion:
Medium concernbecause the vendor has not provided a recent test for the current environment.
Part 15 — Review IAM Controls
Section titled “Part 15 — Review IAM Controls”Assess:
SSO:Available
Customer MFA:Supported through Entra ID
Vendor Workforce MFA:Implemented
Vendor Privileged MFA:Partial
Privileged Access Reviews:Quarterly
Termination:AutomatedControl conclusion:
Partially EffectivePrimary issue:
One legacy privileged account remains outside MFA enforcement.
Part 16 — Review Data Protection
Section titled “Part 16 — Review Data Protection”Vendor reports:
Encryption at Rest:AES-256
Encryption in Transit:TLS 1.2+
Customer Data Segregation:Logical
Backups:Encrypted
Retention:Contract Configurable
Deletion:Within 60 days after terminationAssessment:
Generally EffectiveStudent Action
Section titled “Student Action”Identify one area requiring contractual confirmation.
Recommended:
Confirm contractual data deletion requirement and evidence of deletion.Part 17 — Review Security Monitoring
Section titled “Part 17 — Review Security Monitoring”CloudCollab states:
-
Centralized logging.
-
SIEM monitoring.
-
24×7 SOC coverage.
-
Privileged activity monitoring.
-
Incident escalation process.
Evidence:
-
SOC report.
-
Security monitoring policy.
Assessment:
EffectivePart 18 — Review Vulnerability Management
Section titled “Part 18 — Review Vulnerability Management”Vendor reports:
External Scanning:Continuous
Authenticated Scanning:Monthly
Critical Remediation:15 Days
High Remediation:30 Days
Dependency Scanning:CI/CD IntegratedAssessment:
EffectiveConcern remains:
Penetration test evidence is older than preferred.
Part 19 — Review Incident Response
Section titled “Part 19 — Review Incident Response”Vendor maintains:
-
Incident response plan.
-
Defined incident roles.
-
24×7 security operations.
-
Annual tabletop exercise.
-
Customer notification procedure.
Current contractual notification proposal:
Notification:Within 72 hours of confirming customer impact.NorthStar requires:
Notification:Within 24 hours of identifying a security incident reasonably suspected to affect NorthStar data or services.This creates a contractual gap.
Part 20 — Create Finding 01
Section titled “Part 20 — Create Finding 01”Finding ID:TPR-001
Title:Incomplete MFA Coverage for Privileged Vendor Accounts
Domain:Identity & Access ManagementFinding:
CloudCollab does not currently enforce MFA for one legacy privileged administrative account, increasing the risk of unauthorized privileged access if the account credentials are compromised.
Recommended severity:
HighRecommended remediation:
Enforce MFA or an equivalent phishing-resistant compensating control for the remaining privileged account within 60 days.
Part 21 — Create Finding 02
Section titled “Part 21 — Create Finding 02”Finding ID:TPR-002
Title:Disaster Recovery Testing Not PerformedFinding:
CloudCollab has a documented disaster recovery program but did not perform a DR test during the latest assurance period.
Potential impact:
Unknown recovery capability ↓Potential prolonged service disruptionRecommended severity:
HighRecommended remediation:
Complete a documented disaster recovery exercise and provide test evidence within 120 days.
Part 22 — Create Finding 03
Section titled “Part 22 — Create Finding 03”Finding ID:TPR-003
Title:Penetration Testing Evidence Is OutdatedFinding:
The latest provided independent penetration test was completed in March 2025 and may not represent the current production environment.
Recommended severity:
MediumRecommended remediation:
Provide a current independent penetration-test summary covering the production web application, APIs, and authentication environment within 90 days.
Part 23 — Create Finding 04
Section titled “Part 23 — Create Finding 04”Finding ID:TPR-004
Title:Incident Notification Timeline Does Not Meet NorthStar RequirementVendor position:
72 HoursNorthStar requirement:
24 HoursRecommended severity:
HighRecommended action:
Negotiate a contractual security-incident notification requirement consistent with NorthStar’s regulatory and business obligations.
Part 24 — Review Business Continuity
Section titled “Part 24 — Review Business Continuity”Vendor claims:
RTO:8 hours
RPO:4 hoursNorthStar business requirement:
RTO:4 hours
RPO:4 hoursA gap exists.
Student Action
Section titled “Student Action”Create:
TPR-005
Recovery Time Objective Does Not Meet Business RequirementDetermine appropriate severity.
Recommended:
Medium to Highdepending on business dependency.
For this lab, use:
Highbecause CloudCollab supports critical customer workflows.
Part 25 — Review Fourth Parties
Section titled “Part 25 — Review Fourth Parties”CloudCollab discloses:
Primary Cloud Infrastructure:Major hyperscale cloud provider
Email Delivery:External provider
Customer Support:Third-party support platform
Analytics:External analytics serviceDocument these as fourth-party dependencies.
Part 26 — Evaluate Fourth-Party Management
Section titled “Part 26 — Evaluate Fourth-Party Management”CloudCollab states it:
-
Performs annual reviews.
-
Requires contractual security requirements.
-
Tracks critical suppliers.
-
Maintains subprocessor inventory.
-
Provides customer notification of material subprocessor changes.
Assessment:
Generally EffectiveHowever, NorthStar should require notification of material subprocessor changes.
Part 27 — Create the Vendor Findings Register
Section titled “Part 27 — Create the Vendor Findings Register”Build a worksheet:
Vendor FindingsUse:
| ID | Finding | Domain | Severity | Remediation | Due |
|---|---|---|---|---|---|
| TPR-001 | Privileged MFA gap | IAM | High | Enforce MFA | 60 Days |
| TPR-002 | No DR test | Resilience | High | Perform DR test | 120 Days |
| TPR-003 | Old penetration test | Security Testing | Medium | Perform updated test | 90 Days |
| TPR-004 | Incident notification gap | Incident Response | High | Contract update | Before Go-Live |
| TPR-005 | RTO gap | Resilience | High | Improve recovery / accept risk | Before Go-Live |
Part 28 — Assess Control Effectiveness
Section titled “Part 28 — Assess Control Effectiveness”Use:
| Domain | Rating |
|---|---|
| Governance | Effective |
| IAM | Partially Effective |
| Data Protection | Effective |
| Vulnerability Management | Effective |
| Security Monitoring | Effective |
| Incident Response | Partially Effective |
| Business Continuity | Partially Effective |
| Third-Party Management | Effective |
Overall:
Control Environment:Partially EffectivePart 29 — Calculate Residual Risk
Section titled “Part 29 — Calculate Residual Risk”Initial inherent risk:
22 — Tier 1 Critical VendorNow evaluate residual risk after controls.
Use a simplified vendor-risk model:
| Residual Factor | Score |
|---|---|
| Security Control Weakness | 3 |
| Business Criticality | 4 |
| Data Sensitivity | 4 |
| Assurance Quality | 2 |
| Open High Findings | 4 |
Average or organizational method may be used.
For this lab, assign:
Residual Likelihood = 3
Residual Impact = 4Calculate:
3 × 4 = 12Result:
Residual Risk:HighPart 30 — Determine Vendor Decision
Section titled “Part 30 — Determine Vendor Decision”Possible decisions:
Approve
Approve with Conditions
Escalate for Risk Acceptance
RejectGiven the findings, the recommended decision is:
APPROVE WITH CONDITIONSPart 31 — Define Approval Conditions
Section titled “Part 31 — Define Approval Conditions”Require:
Before Production Use
Section titled “Before Production Use”-
Update incident notification requirement to 24 hours.
-
Agree on acceptable recovery requirements.
-
Confirm NorthStar SSO and MFA configuration.
-
Confirm contractual data deletion requirements.
Within 60 Days
Section titled “Within 60 Days”- Resolve privileged MFA gap.
Within 90 Days
Section titled “Within 90 Days”- Provide current penetration-test evidence.
Within 120 Days
Section titled “Within 120 Days”- Complete disaster recovery exercise and provide evidence.
Part 32 — Risk Acceptance
Section titled “Part 32 — Risk Acceptance”Suppose CloudCollab cannot meet a 4-hour RTO immediately.
The business may request temporary risk acceptance.
Document:
Risk:Vendor recovery may exceed NorthStar business requirement.
Current Vendor RTO:8 Hours
Required:4 Hours
Compensating Controls:Alternative communication processManual workflow capabilityPeriodic data exports
Risk Owner:Director of Customer Operations
Expiration:6 MonthsThis decision should require authorized approval.
Part 33 — Contractual Security Requirements
Section titled “Part 33 — Contractual Security Requirements”Create a worksheet:
Contract Security RequirementsInclude:
-
Security safeguards.
-
Encryption requirements.
-
MFA.
-
Incident notification.
-
Data location.
-
Data retention.
-
Data deletion.
-
Subprocessor notification.
-
Vulnerability management.
-
Penetration testing.
-
Business continuity.
-
Audit rights.
-
Termination assistance.
Part 34 — Example Incident Clause Requirement
Section titled “Part 34 — Example Incident Clause Requirement”Document the requirement:
CloudCollab must notify NorthStar within 24 hours after becoming aware of a security incident reasonably suspected to affect NorthStar information, accounts, systems, or services.
Legal should approve the final contractual language.
Part 35 — Example Data Deletion Requirement
Section titled “Part 35 — Example Data Deletion Requirement”Document:
Upon contract termination, CloudCollab must return or securely delete NorthStar information within the contractually defined period and provide confirmation of deletion where required.
Part 36 — Example Subprocessor Requirement
Section titled “Part 36 — Example Subprocessor Requirement”Document:
CloudCollab must maintain an up-to-date list of material subprocessors and provide advance notification of material changes affecting NorthStar data processing.
Part 37 — Define NorthStar Controls
Section titled “Part 37 — Define NorthStar Controls”Remember the SOC Complementary User Entity Controls.
Create internal actions:
Enable Entra ID SSO.
Enforce NorthStar MFA.
Perform quarterly user access reviews.
Remove terminated-user access.
Protect integration credentials.
Monitor vendor integrations.Vendor security is a shared responsibility.
Part 38 — Create the Assessment Report
Section titled “Part 38 — Create the Assessment Report”Create:
Third-Party Security Risk Assessment ReportRecommended sections:
1. Executive Summary
2. Vendor Overview
3. Business Use Case
4. Assessment Scope
5. Data Classification
6. Inherent Risk
7. Assurance Documents Reviewed
8. Control Assessment
9. Security Findings
10. Residual Risk
11. Contract Requirements
12. Remediation Requirements
13. Approval Recommendation
14. Ongoing MonitoringPart 39 — Executive Summary
Section titled “Part 39 — Executive Summary”Write:
CloudCollab was assessed as a Tier 1 Critical third party because it will process confidential customer and enterprise information and support important customer operations. The vendor maintains a generally mature security program supported by SOC 2 Type II and ISO/IEC 27001 assurance. However, the assessment identified five material concerns, including incomplete privileged MFA, missing disaster recovery testing, outdated penetration-testing evidence, an incident-notification contractual gap, and recovery objectives that do not fully meet NorthStar’s business requirements. Residual vendor risk is rated High. Approval is recommended subject to defined remediation and contractual conditions.
Part 40 — Vendor Risk Summary
Section titled “Part 40 — Vendor Risk Summary”| Item | Result |
|---|---|
| Vendor | CloudCollab |
| Inherent Tier | Tier 1 — Critical |
| Control Environment | Partially Effective |
| High Findings | 4 |
| Medium Findings | 1 |
| Residual Risk | High |
| Recommendation | Approve with Conditions |
This gives leadership a quick decision view.
Part 41 — Ongoing Monitoring Plan
Section titled “Part 41 — Ongoing Monitoring Plan”Because CloudCollab is Tier 1, establish:
Annual Full Reassessment
Annual SOC Review
Annual ISO Certificate Validation
Annual Penetration-Test Review
Continuous Security Incident Monitoring
Quarterly Open-Finding Review
Annual Business Continuity ReviewPart 42 — Trigger-Based Reassessment
Section titled “Part 42 — Trigger-Based Reassessment”Immediate reassessment should occur if:
-
Vendor suffers a material breach.
-
Major subprocessor changes.
-
Service architecture changes significantly.
-
Sensitive-data scope increases.
-
Vendor certification expires.
-
Significant acquisition occurs.
-
Critical security findings emerge.
-
NorthStar increases vendor access.
Part 43 — Reassessment Calendar
Section titled “Part 43 — Reassessment Calendar”Create:
| Activity | Frequency |
|---|---|
| Full Vendor Assessment | Annual |
| SOC Report Review | Annual |
| ISO Validation | Annual |
| Pentest Review | Annual |
| Finding Review | Quarterly |
| Contract Review | Renewal |
| Business Criticality Review | Annual |
Part 44 — Offboarding Requirements
Section titled “Part 44 — Offboarding Requirements”Document future offboarding controls.
At relationship termination:
Disable SSO Integration
Revoke API Credentials
Disable Vendor Accounts
Export Required Data
Delete Vendor Data
Confirm Deletion
Remove Integrations
Update Vendor InventoryPlanning offboarding at onboarding time improves lifecycle security.
Part 45 — Evidence Register
Section titled “Part 45 — Evidence Register”Create:
Vendor Evidence RegisterUse:
| Evidence ID | Document | Period | Status |
|---|---|---|---|
| EVD-001 | SOC 2 Type II | 2025 | Reviewed |
| EVD-002 | ISO 27001 Certificate | Current | Reviewed |
| EVD-003 | Penetration-Test Summary | Mar 2025 | Reviewed |
| EVD-004 | Security Questionnaire | Current | Reviewed |
| EVD-005 | Subprocessor List | Current | Reviewed |
| EVD-006 | Business Continuity Plan | Current | Reviewed |
Part 46 — Evidence Quality Review
Section titled “Part 46 — Evidence Quality Review”For every assurance document, ask:
Is it current?
Is the correct service in scope?
Is the period relevant?
Is the source reliable?
Are exceptions disclosed?
Are there limitations?
Does it address the risk we care about?Never record:
Document Received = Risk ResolvedEvidence must be analyzed.
Part 47 — Risk Decision Matrix
Section titled “Part 47 — Risk Decision Matrix”You can use:
| Residual Risk | Recommendation |
|---|---|
| Low | Approve |
| Moderate | Approve / Monitor |
| High | Conditional Approval / Risk Acceptance |
| Critical | Executive Escalation / Reject |
For CloudCollab:
High ↓Conditional ApprovalPart 48 — Common TPRM Mistakes
Section titled “Part 48 — Common TPRM Mistakes”Mistake 1 — Relying Only on Questionnaires
Section titled “Mistake 1 — Relying Only on Questionnaires”Questionnaires are management assertions.
Validate significant responses with evidence.
Mistake 2 — Treating SOC 2 as a Pass Certificate
Section titled “Mistake 2 — Treating SOC 2 as a Pass Certificate”Always review:
Scope
Period
Exceptions
CUECs
Subservice OrganizationsMistake 3 — Ignoring Business Context
Section titled “Mistake 3 — Ignoring Business Context”The same vendor could be low risk for one use case and critical for another.
Mistake 4 — No Fourth-Party Review
Section titled “Mistake 4 — No Fourth-Party Review”Cloud and SaaS ecosystems depend heavily on subprocessors.
Mistake 5 — No Remediation Tracking
Section titled “Mistake 5 — No Remediation Tracking”Vendor findings should have:
Owner
Target Date
Status
EvidenceMistake 6 — No Reassessment
Section titled “Mistake 6 — No Reassessment”Vendor posture changes over time.
Mistake 7 — Security Review After Contract Signature
Section titled “Mistake 7 — Security Review After Contract Signature”Assessment should happen before significant commitments wherever possible.
Mistake 8 — Forgetting Customer Responsibilities
Section titled “Mistake 8 — Forgetting Customer Responsibilities”A vendor may provide security capabilities that the customer must configure.
Part 49 — Final Deliverables
Section titled “Part 49 — Final Deliverables”Your completed lab should contain:
01 — Vendor Intake
02 — Vendor Data Classification
03 — Inherent Risk Assessment
04 — Vendor Security Questionnaire Review
05 — SOC 2 Review
06 — ISO Certificate Review
07 — Penetration-Test Review
08 — Control Assessment
09 — Vendor Findings Register
10 — Contract Security Requirements
11 — Vendor Evidence Register
12 — Residual Risk Assessment
13 — Ongoing Monitoring Plan
14 — Third-Party Security Risk Assessment ReportLab Validation Checklist
Section titled “Lab Validation Checklist”Before marking this lab complete:
-
Created vendor intake record.
-
Identified business owner.
-
Documented business use case.
-
Identified data classifications.
-
Created vendor data flow.
-
Calculated inherent risk.
-
Assigned vendor risk tier.
-
Reviewed security questionnaire.
-
Reviewed SOC 2 report.
-
Identified SOC exceptions.
-
Identified customer control responsibilities.
-
Reviewed ISO certification.
-
Reviewed penetration-test evidence.
-
Evaluated IAM controls.
-
Evaluated data protection.
-
Evaluated vulnerability management.
-
Evaluated incident response.
-
Evaluated business continuity.
-
Identified fourth-party dependencies.
-
Created five vendor findings.
-
Assigned finding severity.
-
Defined remediation requirements.
-
Calculated residual risk.
-
Defined contractual controls.
-
Recommended approval decision.
-
Created monitoring schedule.
-
Created final risk assessment report.
Expected Skills After This Lab
Section titled “Expected Skills After This Lab”After completing this lab, you should be comfortable performing:
Vendor Intake ↓Business Criticality ↓Data Assessment ↓Inherent Risk ↓Vendor Tiering ↓Security Due Diligence ↓Assurance Review ↓Control Analysis ↓Findings ↓Residual Risk ↓Risk Recommendation ↓Contract Requirements ↓MonitoringThis represents the core workflow of a Third-Party Risk Analyst.
Real-World GRC Perspective
Section titled “Real-World GRC Perspective”In enterprise environments, you may assess:
HundredsorThousandsof VendorsIt is therefore essential to use:
-
Risk-based tiering.
-
Standardized intake.
-
Reusable questionnaires.
-
Evidence templates.
-
Common control libraries.
-
Automated workflows.
-
Centralized findings.
-
Continuous monitoring.
The objective is not to perform the deepest possible assessment on every supplier.
The objective is to apply the appropriate level of assurance based on risk.
Mission Complete
Section titled “Mission Complete”You have completed an end-to-end Third-Party Security Risk Assessment.
You moved from:
Business Wants Vendor ↓TPRM Assessment ↓Security Evidence ↓Control Analysis ↓Risk Findings ↓Residual Risk ↓Management DecisionThis is exactly how GRC helps organizations make informed third-party decisions instead of treating vendor approval as a simple procurement activity.
What’s Next?
Section titled “What’s Next?”➡️ Runbook 01 — Security Control Assessment & Evidence Collection
In the next practical activity, you will build a reusable operational runbook for evaluating enterprise controls and collecting evidence consistently.
You will follow the workflow:
Control Selected ↓Scope Confirmed ↓Control Owner Identified ↓Evidence Requested ↓Population Validated ↓Sample Selected ↓Control Tested ↓Exceptions Documented ↓Effectiveness Determined ↓Remediation Tracked ↓RetestThe runbook will become a repeatable procedure that GRC Analysts can use for internal assessments, external audits, compliance testing, and continuous control assurance.