Skip to main content
CISO-FUNDAMENTALS4 MIN READ

Sort vendor risk signals before renewal

Classify vendor-risk signals so supplier reviews lead to concrete renewal decisions.

Classify each vendor-risk signal into the decision category it should drive. Contract Terms Access Scope Control Evidence Ongoing Monitoring The agreement does not specify customer-specific breach notification timing The vendor API token can read all customer exports but only needs aggregated metrics The SOC 2 report excludes the new data pipeline used by your account Large data exports by vendor service accounts should trigger anomaly review The vendor can add subprocessors without notice or objection rights Four former vendor support users still have portal access The vendor claims resilience but has not provided recent restore-test evidence New vendor-owned domains that…

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us