Classify vendor risk signals into appropriate treatment decisions.
Place each vendor signal into the risk decision bucket it best fits. Accept with rationale Mitigate before use Escalate for risk decision Reject or avoid SOC 2 report ended 45 days before your reliance period, vendor offers bridge letter Critical vendor has no MFA for administrative accounts Security policy review date is two weeks late, but controls and report are current Vendor refuses security addendum while processing production customer data Pen-test summary lists one medium issue with committed remediation date before go-live Low-risk analytics vendor stores only aggregated usage data and has current ISO 27001 certificate Subprocessor location conflicts with…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in