Locked
Vendor Security Assessment Training
By the end, you'll know how to triage vendor risk (tier them), what questions actually matter, how to read security documentation (SOC 2, ISO 27001, pen-test summaries), the contractual minimums every vendor agreement needs, and how to monitor vendors after onboarding.
Procurement, finance, IT, security partners, business leaders evaluating vendors · ~25 min · 6 modules
This course is part of the paid catalog. Purchase it individually, or unlock it with a membership that includes Tier 1 & 2 content.
What's inside
- 01~4 minWhy vendor security is now your problemMost major breaches in the last two years started at a vendor. The shift means every employee who signs SaaS contracts is now a security gatekeeper, whether they realize it or not.
- 02~4 minTier the vendor (so you scrutinize the right ones)Not every vendor needs the same level of review. A tiering system focuses scrutiny on the vendors who could actually hurt you.
- 03~4 minQuestions that actually matterMost vendor security questionnaires ask 250+ generic questions. The questions that actually change vendor behavior — or surface real risk — are fewer. Here are the ones that matter.
- 04~5 minReading SOC 2, ISO 27001, and pen test summaries — what mattersSecurity documentation can look impressive but mean little. Here's what to actually look for in the main types of vendor security evidence.
- 05~4 minContract terms that matter when something goes wrongMost vendor contracts have boilerplate security language that doesn't actually help when something happens. The terms that do help — and how to get them.
- 06~4 minOngoing monitoring and the recapVendor security isn't a one-time pre-onboarding check. Vendors change, get acquired, get breached. Ongoing monitoring is the difference between informed risk and surprise.