โ† All cheat sheets

TPRM

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Third-Party Risk Management (TPRM) is the process of identifying, assessing,
and controlling risks arising from relationships with external vendors,
suppliers, partners, and service providers. Critical as supply chain attacks
and vendor breaches continue to rise.

TPRM LIFECYCLE#

1. Planning & Scoping       - Define program strategy and risk appetite
2. Vendor Identification    - Inventory all third parties
3. Risk Tiering             - Classify vendors by risk level
4. Due Diligence            - Assess security posture before engagement
5. Contracting              - Include security requirements in agreements
6. Onboarding               - Grant appropriate access and monitor
7. Continuous Monitoring    - Ongoing assessment throughout relationship
8. Offboarding              - Revoke access, ensure data return/destruction

RISK TIERING#

Tier vendors based on criticality and data exposure:

Tier 1 - Critical / High Risk:
  - Access to sensitive/regulated data (PII, PHI, financial)
  - Direct access to internal networks or systems
  - Critical business process dependency
  - Cannot be easily replaced
  - Assessment: Full questionnaire + on-site audit + continuous monitoring

Tier 2 - Significant / Medium Risk:
  - Access to non-sensitive internal data
  - Indirect system access (API integrations)
  - Important but not critical to operations
  - Assessment: Standard questionnaire + evidence review + periodic monitoring

Tier 3 - Low Risk:
  - No data access or minimal public data
  - No system access
  - Easily replaceable, minimal business impact
  - Assessment: Basic questionnaire or self-attestation

Tiering Criteria:
  [ ] Type of data accessed (PII, PHI, PCI, confidential, public)
  [ ] Volume of data records
  [ ] System/network access level
  [ ] Business criticality and replaceability
  [ ] Regulatory requirements (SOX, HIPAA, GDPR)
  [ ] Geographic location and jurisdictional risk
  [ ] Financial stability of the vendor
  [ ] Subcontractor (4th party) dependencies

DUE DILIGENCE QUESTIONNAIRES#

SIG (Standardized Information Gathering):
  - Developed by Shared Assessments
  - SIG Core: ~850 questions (comprehensive, for Tier 1)
  - SIG Lite: ~180 questions (streamlined, for Tier 2)
  - Maps to multiple frameworks (ISO, NIST, PCI, HIPAA)
  - Covers 18 risk domains including security, privacy, BCP

CAIQ (Consensus Assessments Initiative Questionnaire):
  - Developed by Cloud Security Alliance (CSA)
  - Specifically designed for cloud service providers
  - Aligns with CSA Cloud Controls Matrix (CCM)
  - Yes/No format with supporting evidence
  - Covers: application security, audit, BCP, change management,
    data security, encryption, governance, identity management,
    infrastructure, interoperability, mobile, networking, security
    incident management, supply chain, threat management

VSAQ (Vendor Security Assessment Questionnaire):
  - Google's open-source questionnaire framework
  - Web-based, customizable templates
  - Multiple assessment types for different scenarios

Other Assessment Tools:
  - SOC 2 Type II reports (Service Organization Controls)
  - ISO 27001 certification
  - PCI DSS Attestation of Compliance (AoC)
  - HITRUST CSF certification
  - Penetration test reports (executive summary)
  - CSA STAR registry
  - External security ratings (BitSight, SecurityScorecard, RiskRecon)

DUE DILIGENCE CHECKLIST#

[ ] Information security policies and governance structure
[ ] Access control and identity management practices
[ ] Data encryption (at rest, in transit, key management)
[ ] Vulnerability management and patching cadence
[ ] Incident response plan and breach notification process
[ ] Business continuity and disaster recovery plans (tested)
[ ] Employee background checks and security training
[ ] Physical security controls
[ ] Network segmentation and monitoring
[ ] Change management processes
[ ] Subcontractor/4th party management
[ ] Regulatory compliance status and certifications
[ ] Data retention and destruction policies
[ ] Privacy practices and data processing agreements
[ ] Insurance coverage (cyber liability)
[ ] Financial stability (Dun & Bradstreet, credit reports)

CONTRACT SECURITY CLAUSES#

Data Protection:
  [ ] Define data classification and handling requirements
  [ ] Specify encryption standards (AES-256, TLS 1.2+)
  [ ] Data processing agreement (DPA) for personal data
  [ ] Data residency and sovereignty requirements
  [ ] Data return and secure destruction upon termination

Access and Security:
  [ ] Multi-factor authentication requirement
  [ ] Principle of least privilege for all access
  [ ] Background checks for personnel with access
  [ ] Security awareness training requirements
  [ ] Segregation of client data in multi-tenant environments

Incident and Breach:
  [ ] Breach notification timeline (24-72 hours)
  [ ] Define what constitutes a security incident
  [ ] Cooperation requirements during investigations
  [ ] Forensic evidence preservation obligations
  [ ] Liability and indemnification for breaches

Compliance and Audit:
  [ ] Right to audit clause (with reasonable notice)
  [ ] Annual SOC 2 Type II or equivalent report
  [ ] Compliance with applicable regulations
  [ ] Penetration testing requirements (annual minimum)
  [ ] Vulnerability scan results sharing

Subcontracting:
  [ ] Prior written approval for subcontractors
  [ ] Flow-down of security requirements to subcontractors
  [ ] Maintain list of approved subcontractors
  [ ] Notification of subcontractor changes

Termination:
  [ ] Data return in standard format within defined period
  [ ] Certificate of data destruction (NIST 800-88 compliant)
  [ ] Transition assistance period and obligations
  [ ] Survival clauses for confidentiality and data protection

SLA REQUIREMENTS#

Availability:
  - Uptime guarantee (99.9% = 8.76 hours downtime/year)
  - 99.95% = 4.38 hours/year, 99.99% = 52.6 minutes/year
  - Planned maintenance windows and notification periods
  - Penalties/credits for SLA breaches

Performance:
  - Response time thresholds
  - Transaction processing capacity
  - Throughput and latency requirements
  - Scalability commitments

Support:
  - Severity level definitions (P1-P4)
  - Response times by severity (P1: 15 min, P2: 1 hour, etc.)
  - Resolution time targets
  - Escalation procedures and contacts
  - 24/7 support availability for critical issues

Security SLAs:
  - Vulnerability remediation timelines
    Critical: 24-48 hours
    High: 7 days
    Medium: 30 days
    Low: 90 days
  - Security patch deployment timelines
  - Incident detection and response time targets
  - Recovery Time Objective (RTO) and Recovery Point Objective (RPO)

INCIDENT NOTIFICATION REQUIREMENTS#

Define in contract:
  [ ] Who to notify (security team, DPO, legal, executives)
  [ ] Notification method (phone, email, secure portal)
  [ ] Initial notification timeline (e.g., 24 hours of discovery)
  [ ] Follow-up reporting cadence and content requirements
  [ ] Root cause analysis (RCA) delivery timeline
  [ ] Remediation plan and evidence of implementation
  [ ] Cooperation with client's IR team and forensic investigators
  [ ] Preservation of logs and forensic evidence

RIGHT TO AUDIT#

  [ ] Right to conduct audits with reasonable notice (30 days)
  [ ] Audit scope includes security controls, processes, facilities
  [ ] Option to use qualified third-party auditor
  [ ] Vendor cooperation and access to personnel, systems, records
  [ ] Accept SOC 2 or ISO 27001 as partial audit substitute
  [ ] Frequency: annual minimum, additional upon material change or incident
  [ ] Remediation requirements with defined timelines for findings
  [ ] Cost allocation (who pays for audits)

CONTINUOUS MONITORING#

External Monitoring:
  [ ] Security ratings platforms (BitSight, SecurityScorecard)
  [ ] Dark web monitoring for vendor data exposure
  [ ] Domain/certificate monitoring
  [ ] Public breach databases and news monitoring
  [ ] Regulatory action monitoring
  [ ] Financial health monitoring

Periodic Assessments:
  [ ] Annual reassessment questionnaire (Tier 1 and 2)
  [ ] Annual SOC 2 Type II report review
  [ ] Annual penetration test report review
  [ ] Quarterly business review meetings
  [ ] Review of significant changes (M&A, leadership, infrastructure)

Automated Monitoring:
  [ ] Vendor risk management platforms (OneTrust, Prevalent, ProcessUnity)
  [ ] Integration with security ratings into risk dashboards
  [ ] Automated alerts for rating changes or exposures
  [ ] Contract expiration and renewal tracking

KEY METRICS FOR TPRM#

- Total number of third parties by risk tier
- Percentage of vendors assessed within the last 12 months
- Average time to complete vendor risk assessment
- Number of critical/high findings per vendor
- Remediation rate and time to remediate findings
- Number of vendor-related security incidents
- Percentage of contracts with required security clauses
- Average security rating score across vendor portfolio
- Number of vendors with expired certifications/assessments

COMMON TPRM PITFALLS#

- Incomplete vendor inventory (shadow IT vendors)
- One-time assessment without ongoing monitoring
- Treating all vendors the same regardless of risk
- Missing 4th party (subcontractor) risk
- No exit strategy or offboarding process
- Contracts without adequate security requirements
- Not validating questionnaire responses with evidence
- Failing to track remediation of identified issues
- Lack of executive sponsorship and accountability
- Not integrating TPRM with overall enterprise risk management