VENDOR-RISK5 MIN READ
Sort Vendor Findings by Risk Treatment
classify findings into accept, mitigate, transfer, or avoid
Drag each card into the right bucket, then check your score. Accept with owner Mitigate before launch Transfer in contract Avoid or replace No formal incident notification timeline No MFA for vendor admins Minor policy review overdue by two weeks Vendor refuses audit rights for critical service No exit assistance clause Unpatched internet-facing admin panel Vendor will not commit to 24-hour breach notice Backup restore test is six months late No encryption for regulated exports Vendor cannot support required data residency
Read the full lesson
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in