Skip to content

Lab 02 — Perform a Third-Party Security Risk Assessment

Item Details
Lab Lab 02 — Perform a Third-Party Security Risk Assessment
Module 01 — GRC Fundamentals
Difficulty Intermediate
Estimated Time 120–150 Minutes
Role GRC Analyst / Third-Party Risk Analyst
Primary Deliverable Third-Party Security Risk Assessment Report
Environment Spreadsheet / GRC Workspace / Documentation Tool
Lab Type Third-Party Risk Management

NorthStar Digital Services is considering purchasing a new SaaS platform called CloudCollab.

CloudCollab will be used by multiple business teams to manage customer projects, documents, collaboration, and workflow automation.

The proposed service will:

  • Be used by approximately 1,500 employees.

  • Process customer contact information.

  • Store internal confidential documents.

  • Integrate with Microsoft Entra ID.

  • Support SSO.

  • Receive user profile information.

  • Store application data in the cloud.

  • Use several subprocessors.

  • Support business-critical customer operations.

The business team wants the vendor approved quickly.

However, before a contract can be signed, NorthStar’s Third-Party Risk Management team requires a formal security assessment.

You have been assigned as the GRC / Third-Party Risk Analyst responsible for the assessment.

Your responsibility is to determine:

What risk does this vendor introduce?
What data will it process?
How critical is the service?
What controls does the vendor have?
What evidence supports those controls?
What gaps exist?
What residual risk remains?
Can the vendor be approved?
What conditions should apply?

By completing this lab, you will learn how to:

  • Perform vendor intake.

  • Identify the business owner.

  • Determine data sensitivity.

  • Determine business criticality.

  • Assess inherent third-party risk.

  • Assign a vendor risk tier.

  • Perform security due diligence.

  • Review a vendor security questionnaire.

  • Review SOC 2 assurance.

  • Review ISO/IEC 27001 certification.

  • Review penetration-testing evidence.

  • Evaluate IAM controls.

  • Evaluate data-protection controls.

  • Evaluate vulnerability management.

  • Evaluate incident response.

  • Evaluate business continuity.

  • Identify fourth-party dependencies.

  • Document vendor findings.

  • Calculate residual risk.

  • Recommend remediation.

  • Make an approval recommendation.

  • Build a professional Third-Party Risk Assessment Report.

Before beginning this lab, you should understand:

  • Third-Party Risk Management.

  • Enterprise risk management.

  • Risk assessment methodology.

  • Control design.

  • Control testing.

  • Audit and assurance.

  • Compliance management.

Recommended lessons:

03 Enterprise Risk Management
04 Risk Assessment Methodology
07 Control Design & Implementation
08 Control Testing & Effectiveness
09 Audit & Assurance Fundamentals
10 Compliance Management
11 Third-Party Risk Management

You will follow this workflow:

Vendor Request
Vendor Intake
Inherent Risk Assessment
Vendor Tiering
Security Questionnaire
Evidence Review
Control Assessment
Security Findings
Residual Risk
Remediation
Risk Decision
Approval / Rejection
Ongoing Monitoring

Part 1 — Create the Vendor Intake Record

Section titled “Part 1 — Create the Vendor Intake Record”

Create a worksheet or document named:

Vendor Intake

Use the following fields:

Field Value
Vendor Name CloudCollab
Service SaaS Collaboration Platform
Business Owner Director of Customer Operations
Users 1,500
Hosting Model SaaS
Identity Integration Microsoft Entra ID / SSO
Business Criticality High
Customer Data Yes
Confidential Data Yes
Personal Data Yes
Payment Data No
Production Access No direct access to NorthStar infrastructure
External Integration Yes
Subprocessors Yes

Part 2 — Understand the Business Use Case

Section titled “Part 2 — Understand the Business Use Case”

Document why the vendor is required.

Example:

CloudCollab will provide centralized project collaboration, document management, customer workflow tracking, and internal team coordination.

Ask:

  • Which teams will use it?

  • What happens if it becomes unavailable?

  • What information will be stored?

  • How long will data remain?

  • Will customers depend on it?

  • Are alternative systems available?

Write a short Business Impact Statement.

Example structure:

Loss of CloudCollab for an extended period could disrupt customer project coordination and internal business workflows, resulting in productivity loss, delayed customer services, and potential contractual impact.

Create:

Vendor Data Classification

Consider these categories:

Data Type Present? Classification
Public Information Yes Public
Employee Names Yes Internal
Customer Contact Data Yes Confidential
Internal Documents Yes Confidential
Authentication Metadata Yes Confidential
Payment Card Data No
Health Data No
Credentials No direct passwords expected Restricted if present

Identify whether any additional data categories may be processed.

Create a simple data flow:

NorthStar User
Microsoft Entra ID
SSO Authentication
CloudCollab
Vendor Cloud Environment
Database / Storage
Vendor Subprocessors

Document:

  • Source of data.

  • Authentication flow.

  • Storage location.

  • Data-processing locations.

  • Subprocessor involvement.

  • Data return/deletion process.

Third-party risk cannot be understood without knowing where data travels.

Part 5 — Perform Inherent Risk Assessment

Section titled “Part 5 — Perform Inherent Risk Assessment”

Assess risk before considering vendor controls.

Use the following categories.

Risk Factor Score
Data Sensitivity 1–5
Business Criticality 1–5
User Population 1–5
System Integration 1–5
Regulatory Impact 1–5
Subprocessor Dependency 1–5

For CloudCollab, use:

Data Sensitivity = 4
Business Criticality = 4
User Population = 4
System Integration = 3
Regulatory Impact = 3
Subprocessor Dependency = 4

Add the scores:

4 + 4 + 4 + 3 + 3 + 4 = 22

Use this tiering model:

Score Tier
6–10 Tier 4 — Low
11–16 Tier 3 — Moderate
17–21 Tier 2 — High
22–30 Tier 1 — Critical

CloudCollab score:

22

Therefore:

Vendor Tier:
Tier 1 — Critical

This means enhanced due diligence is required.

Part 7 — Determine Assessment Requirements

Section titled “Part 7 — Determine Assessment Requirements”

For a Tier 1 vendor, require:

  • Full security questionnaire.

  • SOC 2 Type II report.

  • ISO/IEC 27001 certificate.

  • Penetration-test summary.

  • Business continuity information.

  • Incident-response information.

  • Privacy documentation.

  • Subprocessor inventory.

  • Security findings review.

  • Contractual security review.

Create an assessment checklist.

Part 8 — Review the Vendor Security Questionnaire

Section titled “Part 8 — Review the Vendor Security Questionnaire”

Assume CloudCollab provides the following responses.

Domain Vendor Response
Information Security Program Yes
Security Policies Yes
Dedicated Security Team Yes
MFA for Workforce Yes
MFA for Privileged Users Partial
SSO Support Yes
Encryption at Rest Yes
Encryption in Transit Yes
Vulnerability Scanning Yes
Penetration Testing Yes
SIEM / Security Monitoring Yes
Incident Response Plan Yes
Annual IR Testing Yes
Business Continuity Plan Yes
Annual DR Test No
Vendor Risk Program Yes
Security Awareness Yes
Secure SDLC Yes
Subprocessor Assessments Yes

Part 9 — Identify Questionnaire Concerns

Section titled “Part 9 — Identify Questionnaire Concerns”

Immediately flag:

Concern 1:
Privileged MFA only partially implemented.
Concern 2:
No annual disaster recovery test.

Do not yet determine final severity.

Evidence review comes next.

Assume CloudCollab provides a SOC 2 Type II report.

Report details:

Report Type:
SOC 2 Type II
Period:
1 January – 31 December 2025
Criteria:
Security
Availability
Confidentiality
Service:
CloudCollab SaaS Platform
Auditor Opinion:
Unmodified

The report includes two exceptions.

Four privileged administrator accounts were temporarily excluded from MFA during a system migration.

Vendor response:

Three accounts remediated.
One legacy administrative account remains without MFA.

Disaster recovery test was not performed during the assessment period.

Vendor response:

Test planned for Q4 2026.

These exceptions directly support your questionnaire concerns.

Part 12 — Review Complementary User Entity Controls

Section titled “Part 12 — Review Complementary User Entity Controls”

The SOC report lists:

Customer Responsibilities:
Enable SSO.
Configure MFA through corporate identity provider.
Periodically review user access.
Remove access for terminated employees.
Secure integration credentials.

Document these as NorthStar Responsibilities.

They must eventually become internal controls.

Part 13 — Review ISO/IEC 27001 Certification

Section titled “Part 13 — Review ISO/IEC 27001 Certification”

CloudCollab provides:

Certification:
ISO/IEC 27001
Status:
Valid
Scope:
CloudCollab SaaS platform, supporting production operations, security, engineering, and customer support.
Expiration:
30 June 2027

Assessment conclusion:

Certification appears relevant and in scope.

However:

ISO certification does not eliminate the need to evaluate specific control weaknesses.

Part 14 — Review Penetration-Test Evidence

Section titled “Part 14 — Review Penetration-Test Evidence”

CloudCollab provides an independent penetration-test summary.

Details:

Testing Date:
March 2025
Scope:
External web application
API
Authentication
Critical Findings:
0
High Findings:
2
Medium Findings:
6

Status:

Both High findings:
Remediated
Retest:
Completed

However, the assessment is now more than a year old.

Determine whether the age of the penetration test should create a finding.

Recommended conclusion:

Medium concern

because the vendor has not provided a recent test for the current environment.

Assess:

SSO:
Available
Customer MFA:
Supported through Entra ID
Vendor Workforce MFA:
Implemented
Vendor Privileged MFA:
Partial
Privileged Access Reviews:
Quarterly
Termination:
Automated

Control conclusion:

Partially Effective

Primary issue:

One legacy privileged account remains outside MFA enforcement.

Vendor reports:

Encryption at Rest:
AES-256
Encryption in Transit:
TLS 1.2+
Customer Data Segregation:
Logical
Backups:
Encrypted
Retention:
Contract Configurable
Deletion:
Within 60 days after termination

Assessment:

Generally Effective

Identify one area requiring contractual confirmation.

Recommended:

Confirm contractual data deletion requirement and evidence of deletion.

CloudCollab states:

  • Centralized logging.

  • SIEM monitoring.

  • 24×7 SOC coverage.

  • Privileged activity monitoring.

  • Incident escalation process.

Evidence:

  • SOC report.

  • Security monitoring policy.

Assessment:

Effective

Part 18 — Review Vulnerability Management

Section titled “Part 18 — Review Vulnerability Management”

Vendor reports:

External Scanning:
Continuous
Authenticated Scanning:
Monthly
Critical Remediation:
15 Days
High Remediation:
30 Days
Dependency Scanning:
CI/CD Integrated

Assessment:

Effective

Concern remains:

Penetration test evidence is older than preferred.

Vendor maintains:

  • Incident response plan.

  • Defined incident roles.

  • 24×7 security operations.

  • Annual tabletop exercise.

  • Customer notification procedure.

Current contractual notification proposal:

Notification:
Within 72 hours of confirming customer impact.

NorthStar requires:

Notification:
Within 24 hours of identifying a security incident reasonably suspected to affect NorthStar data or services.

This creates a contractual gap.

Finding ID:
TPR-001
Title:
Incomplete MFA Coverage for Privileged Vendor Accounts
Domain:
Identity & Access Management

Finding:

CloudCollab does not currently enforce MFA for one legacy privileged administrative account, increasing the risk of unauthorized privileged access if the account credentials are compromised.

Recommended severity:

High

Recommended remediation:

Enforce MFA or an equivalent phishing-resistant compensating control for the remaining privileged account within 60 days.

Finding ID:
TPR-002
Title:
Disaster Recovery Testing Not Performed

Finding:

CloudCollab has a documented disaster recovery program but did not perform a DR test during the latest assurance period.

Potential impact:

Unknown recovery capability
Potential prolonged service disruption

Recommended severity:

High

Recommended remediation:

Complete a documented disaster recovery exercise and provide test evidence within 120 days.

Finding ID:
TPR-003
Title:
Penetration Testing Evidence Is Outdated

Finding:

The latest provided independent penetration test was completed in March 2025 and may not represent the current production environment.

Recommended severity:

Medium

Recommended remediation:

Provide a current independent penetration-test summary covering the production web application, APIs, and authentication environment within 90 days.

Finding ID:
TPR-004
Title:
Incident Notification Timeline Does Not Meet NorthStar Requirement

Vendor position:

72 Hours

NorthStar requirement:

24 Hours

Recommended severity:

High

Recommended action:

Negotiate a contractual security-incident notification requirement consistent with NorthStar’s regulatory and business obligations.

Vendor claims:

RTO:
8 hours
RPO:
4 hours

NorthStar business requirement:

RTO:
4 hours
RPO:
4 hours

A gap exists.

Create:

TPR-005
Recovery Time Objective Does Not Meet Business Requirement

Determine appropriate severity.

Recommended:

Medium to High

depending on business dependency.

For this lab, use:

High

because CloudCollab supports critical customer workflows.

CloudCollab discloses:

Primary Cloud Infrastructure:
Major hyperscale cloud provider
Email Delivery:
External provider
Customer Support:
Third-party support platform
Analytics:
External analytics service

Document these as fourth-party dependencies.

Part 26 — Evaluate Fourth-Party Management

Section titled “Part 26 — Evaluate Fourth-Party Management”

CloudCollab states it:

  • Performs annual reviews.

  • Requires contractual security requirements.

  • Tracks critical suppliers.

  • Maintains subprocessor inventory.

  • Provides customer notification of material subprocessor changes.

Assessment:

Generally Effective

However, NorthStar should require notification of material subprocessor changes.

Part 27 — Create the Vendor Findings Register

Section titled “Part 27 — Create the Vendor Findings Register”

Build a worksheet:

Vendor Findings

Use:

ID Finding Domain Severity Remediation Due
TPR-001 Privileged MFA gap IAM High Enforce MFA 60 Days
TPR-002 No DR test Resilience High Perform DR test 120 Days
TPR-003 Old penetration test Security Testing Medium Perform updated test 90 Days
TPR-004 Incident notification gap Incident Response High Contract update Before Go-Live
TPR-005 RTO gap Resilience High Improve recovery / accept risk Before Go-Live

Use:

Domain Rating
Governance Effective
IAM Partially Effective
Data Protection Effective
Vulnerability Management Effective
Security Monitoring Effective
Incident Response Partially Effective
Business Continuity Partially Effective
Third-Party Management Effective

Overall:

Control Environment:
Partially Effective

Initial inherent risk:

22 — Tier 1 Critical Vendor

Now evaluate residual risk after controls.

Use a simplified vendor-risk model:

Residual Factor Score
Security Control Weakness 3
Business Criticality 4
Data Sensitivity 4
Assurance Quality 2
Open High Findings 4

Average or organizational method may be used.

For this lab, assign:

Residual Likelihood = 3
Residual Impact = 4

Calculate:

3 × 4 = 12

Result:

Residual Risk:
High

Possible decisions:

Approve
Approve with Conditions
Escalate for Risk Acceptance
Reject

Given the findings, the recommended decision is:

APPROVE WITH CONDITIONS

Require:

  • Update incident notification requirement to 24 hours.

  • Agree on acceptable recovery requirements.

  • Confirm NorthStar SSO and MFA configuration.

  • Confirm contractual data deletion requirements.

  • Resolve privileged MFA gap.
  • Provide current penetration-test evidence.
  • Complete disaster recovery exercise and provide evidence.

Suppose CloudCollab cannot meet a 4-hour RTO immediately.

The business may request temporary risk acceptance.

Document:

Risk:
Vendor recovery may exceed NorthStar business requirement.
Current Vendor RTO:
8 Hours
Required:
4 Hours
Compensating Controls:
Alternative communication process
Manual workflow capability
Periodic data exports
Risk Owner:
Director of Customer Operations
Expiration:
6 Months

This decision should require authorized approval.

Part 33 — Contractual Security Requirements

Section titled “Part 33 — Contractual Security Requirements”

Create a worksheet:

Contract Security Requirements

Include:

  • Security safeguards.

  • Encryption requirements.

  • MFA.

  • Incident notification.

  • Data location.

  • Data retention.

  • Data deletion.

  • Subprocessor notification.

  • Vulnerability management.

  • Penetration testing.

  • Business continuity.

  • Audit rights.

  • Termination assistance.

Part 34 — Example Incident Clause Requirement

Section titled “Part 34 — Example Incident Clause Requirement”

Document the requirement:

CloudCollab must notify NorthStar within 24 hours after becoming aware of a security incident reasonably suspected to affect NorthStar information, accounts, systems, or services.

Legal should approve the final contractual language.

Part 35 — Example Data Deletion Requirement

Section titled “Part 35 — Example Data Deletion Requirement”

Document:

Upon contract termination, CloudCollab must return or securely delete NorthStar information within the contractually defined period and provide confirmation of deletion where required.

Part 36 — Example Subprocessor Requirement

Section titled “Part 36 — Example Subprocessor Requirement”

Document:

CloudCollab must maintain an up-to-date list of material subprocessors and provide advance notification of material changes affecting NorthStar data processing.

Remember the SOC Complementary User Entity Controls.

Create internal actions:

Enable Entra ID SSO.
Enforce NorthStar MFA.
Perform quarterly user access reviews.
Remove terminated-user access.
Protect integration credentials.
Monitor vendor integrations.

Vendor security is a shared responsibility.

Create:

Third-Party Security Risk Assessment Report

Recommended sections:

1. Executive Summary
2. Vendor Overview
3. Business Use Case
4. Assessment Scope
5. Data Classification
6. Inherent Risk
7. Assurance Documents Reviewed
8. Control Assessment
9. Security Findings
10. Residual Risk
11. Contract Requirements
12. Remediation Requirements
13. Approval Recommendation
14. Ongoing Monitoring

Write:

CloudCollab was assessed as a Tier 1 Critical third party because it will process confidential customer and enterprise information and support important customer operations. The vendor maintains a generally mature security program supported by SOC 2 Type II and ISO/IEC 27001 assurance. However, the assessment identified five material concerns, including incomplete privileged MFA, missing disaster recovery testing, outdated penetration-testing evidence, an incident-notification contractual gap, and recovery objectives that do not fully meet NorthStar’s business requirements. Residual vendor risk is rated High. Approval is recommended subject to defined remediation and contractual conditions.

Item Result
Vendor CloudCollab
Inherent Tier Tier 1 — Critical
Control Environment Partially Effective
High Findings 4
Medium Findings 1
Residual Risk High
Recommendation Approve with Conditions

This gives leadership a quick decision view.

Because CloudCollab is Tier 1, establish:

Annual Full Reassessment
Annual SOC Review
Annual ISO Certificate Validation
Annual Penetration-Test Review
Continuous Security Incident Monitoring
Quarterly Open-Finding Review
Annual Business Continuity Review

Immediate reassessment should occur if:

  • Vendor suffers a material breach.

  • Major subprocessor changes.

  • Service architecture changes significantly.

  • Sensitive-data scope increases.

  • Vendor certification expires.

  • Significant acquisition occurs.

  • Critical security findings emerge.

  • NorthStar increases vendor access.

Create:

Activity Frequency
Full Vendor Assessment Annual
SOC Report Review Annual
ISO Validation Annual
Pentest Review Annual
Finding Review Quarterly
Contract Review Renewal
Business Criticality Review Annual

Document future offboarding controls.

At relationship termination:

Disable SSO Integration
Revoke API Credentials
Disable Vendor Accounts
Export Required Data
Delete Vendor Data
Confirm Deletion
Remove Integrations
Update Vendor Inventory

Planning offboarding at onboarding time improves lifecycle security.

Create:

Vendor Evidence Register

Use:

Evidence ID Document Period Status
EVD-001 SOC 2 Type II 2025 Reviewed
EVD-002 ISO 27001 Certificate Current Reviewed
EVD-003 Penetration-Test Summary Mar 2025 Reviewed
EVD-004 Security Questionnaire Current Reviewed
EVD-005 Subprocessor List Current Reviewed
EVD-006 Business Continuity Plan Current Reviewed

For every assurance document, ask:

Is it current?
Is the correct service in scope?
Is the period relevant?
Is the source reliable?
Are exceptions disclosed?
Are there limitations?
Does it address the risk we care about?

Never record:

Document Received = Risk Resolved

Evidence must be analyzed.

You can use:

Residual Risk Recommendation
Low Approve
Moderate Approve / Monitor
High Conditional Approval / Risk Acceptance
Critical Executive Escalation / Reject

For CloudCollab:

High
Conditional Approval

Mistake 1 — Relying Only on Questionnaires

Section titled “Mistake 1 — Relying Only on Questionnaires”

Questionnaires are management assertions.

Validate significant responses with evidence.

Mistake 2 — Treating SOC 2 as a Pass Certificate

Section titled “Mistake 2 — Treating SOC 2 as a Pass Certificate”

Always review:

Scope
Period
Exceptions
CUECs
Subservice Organizations

The same vendor could be low risk for one use case and critical for another.

Cloud and SaaS ecosystems depend heavily on subprocessors.

Vendor findings should have:

Owner
Target Date
Status
Evidence

Vendor posture changes over time.

Mistake 7 — Security Review After Contract Signature

Section titled “Mistake 7 — Security Review After Contract Signature”

Assessment should happen before significant commitments wherever possible.

Mistake 8 — Forgetting Customer Responsibilities

Section titled “Mistake 8 — Forgetting Customer Responsibilities”

A vendor may provide security capabilities that the customer must configure.

Your completed lab should contain:

01 — Vendor Intake
02 — Vendor Data Classification
03 — Inherent Risk Assessment
04 — Vendor Security Questionnaire Review
05 — SOC 2 Review
06 — ISO Certificate Review
07 — Penetration-Test Review
08 — Control Assessment
09 — Vendor Findings Register
10 — Contract Security Requirements
11 — Vendor Evidence Register
12 — Residual Risk Assessment
13 — Ongoing Monitoring Plan
14 — Third-Party Security Risk Assessment Report

Before marking this lab complete:

  • Created vendor intake record.

  • Identified business owner.

  • Documented business use case.

  • Identified data classifications.

  • Created vendor data flow.

  • Calculated inherent risk.

  • Assigned vendor risk tier.

  • Reviewed security questionnaire.

  • Reviewed SOC 2 report.

  • Identified SOC exceptions.

  • Identified customer control responsibilities.

  • Reviewed ISO certification.

  • Reviewed penetration-test evidence.

  • Evaluated IAM controls.

  • Evaluated data protection.

  • Evaluated vulnerability management.

  • Evaluated incident response.

  • Evaluated business continuity.

  • Identified fourth-party dependencies.

  • Created five vendor findings.

  • Assigned finding severity.

  • Defined remediation requirements.

  • Calculated residual risk.

  • Defined contractual controls.

  • Recommended approval decision.

  • Created monitoring schedule.

  • Created final risk assessment report.

After completing this lab, you should be comfortable performing:

Vendor Intake
Business Criticality
Data Assessment
Inherent Risk
Vendor Tiering
Security Due Diligence
Assurance Review
Control Analysis
Findings
Residual Risk
Risk Recommendation
Contract Requirements
Monitoring

This represents the core workflow of a Third-Party Risk Analyst.

In enterprise environments, you may assess:

Hundreds
or
Thousands
of Vendors

It is therefore essential to use:

  • Risk-based tiering.

  • Standardized intake.

  • Reusable questionnaires.

  • Evidence templates.

  • Common control libraries.

  • Automated workflows.

  • Centralized findings.

  • Continuous monitoring.

The objective is not to perform the deepest possible assessment on every supplier.

The objective is to apply the appropriate level of assurance based on risk.

You have completed an end-to-end Third-Party Security Risk Assessment.

You moved from:

Business Wants Vendor
TPRM Assessment
Security Evidence
Control Analysis
Risk Findings
Residual Risk
Management Decision

This is exactly how GRC helps organizations make informed third-party decisions instead of treating vendor approval as a simple procurement activity.

➡️ Runbook 01 — Security Control Assessment & Evidence Collection

In the next practical activity, you will build a reusable operational runbook for evaluating enterprise controls and collecting evidence consistently.

You will follow the workflow:

Control Selected
Scope Confirmed
Control Owner Identified
Evidence Requested
Population Validated
Sample Selected
Control Tested
Exceptions Documented
Effectiveness Determined
Remediation Tracked
Retest

The runbook will become a repeatable procedure that GRC Analysts can use for internal assessments, external audits, compliance testing, and continuous control assurance.