3. Vendor incident response plans
✔ Has a documented incident response plan outlining security breach management practices.
✔ Has established a business continuity and disaster recovery plan in the event of a cyber incident, including data recovery.
✔ Has a communication plan to notify customers of cyber incidents.
4. Vendor governance
✔ Has provided evidence of certifications including SOC reports, ISO 27001, or HiTrust. Each is considered an international standard for validating a cybersecurity program—internally and across third parties.
✔ Has presented proof of compliance with regulations such as HIPAA, PCI DSS, NERC CIP, FISMA, and more.
✔ Security practices adhere to security frameworks, including NIST and CIS Controls.
✔ Has provided documentation evidencing current cybersecurity insurance.
✔ Reviews security questionnaires, such as the Consensus Assessments Initiative Questionnaire (CAIQ & CAIQ Lite) for assessing cloud providers and the Standardized Information Gathering Questionnaire (SIG Core and SIG Lite).
Continuously assess vendor risk, beyond the onboarding checklist
As your vendor portfolio expands, it’s critical that you find a way to manage vendor risk from procurement all the way through the entire vendor relationship—efficiently and at scale.
A scalable, end-to-end VRM program is one that continuously detects, monitors, and mitigates vendor risk. It goes beyond initial assessments, checklists, and due diligence to constantly reassess and act on vendor risk. Most importantly, it scales with business growth, managing thousands of vendors as effectively as it manages ten.
Bitsight VRM, which combines workflow automation with objective data about your vendors’ security postures, is key to this approach. With Bitsight VRM you have unparalleled visibility over the digital supply chain by measuring and continuously monitoring third-party security controls, ultimately aligning the program with your risk tolerance and organizational objectives.
Take a look at how Alameda Alliance for Health uses Bitsight VRM to conduct the entire vendor assessment and management process in one centralized location, improving efficiency across their VRM program.