FΛForgeAwareness
Locked

Vendor Security Assessment Training

By the end, you'll know how to triage vendor risk (tier them), what questions actually matter, how to read security documentation (SOC 2, ISO 27001, pen-test summaries), the contractual minimums every vendor agreement needs, and how to monitor vendors after onboarding.

Procurement, finance, IT, security partners, business leaders evaluating vendors · ~25 min · 6 modules

This course is part of the paid catalog. Purchase it individually, or unlock it with a membership that includes Tier 1 & 2 content.

What's inside

  1. 01
    Why vendor security is now your problem
    Most major breaches in the last two years started at a vendor. The shift means every employee who signs SaaS contracts is now a security gatekeeper, whether they realize it or not.
    ~4 min
  2. 02
    Tier the vendor (so you scrutinize the right ones)
    Not every vendor needs the same level of review. A tiering system focuses scrutiny on the vendors who could actually hurt you.
    ~4 min
  3. 03
    Questions that actually matter
    Most vendor security questionnaires ask 250+ generic questions. The questions that actually change vendor behavior — or surface real risk — are fewer. Here are the ones that matter.
    ~4 min
  4. 04
    Reading SOC 2, ISO 27001, and pen test summaries — what matters
    Security documentation can look impressive but mean little. Here's what to actually look for in the main types of vendor security evidence.
    ~5 min
  5. 05
    Contract terms that matter when something goes wrong
    Most vendor contracts have boilerplate security language that doesn't actually help when something happens. The terms that do help — and how to get them.
    ~4 min
  6. 06
    Ongoing monitoring and the recap
    Vendor security isn't a one-time pre-onboarding check. Vendors change, get acquired, get breached. Ongoing monitoring is the difference between informed risk and surprise.
    ~4 min