As the importance of third-party risk management (TPRM) continues to grow, organizations are hiring for related roles more seriously than ever before. To compensate, security and risk professionals are seeking out certification programs in TPRM to learn new skills and validate their expertise.
A number of technical certifications have popped up in recent years to meet this increasing demand, each catering to different specialties. How do you know which certification program is right for you? Is more technical education even the right choice for your needs?
TPRM certification: Why do you need it?
TPRM training is important because the risk associated with third- (and, increasingly, fourth-) party vendors is growing at an alarming rate. In recent years, cybercriminals have used insecure vendor software to penetrate organizations ranging from government agencies to big-box retailers to public utility companies.
Organizations are looking for IT security professionals who are versed in up-to-date cybersecurity frameworks and any applicable cybersecurity regulations. Certification programs help ensure that new hires have the right stuff for the job.
TPRM requires more than technical skills
As valuable as technical certifications can be, it’s important to understand that supporting or leading a successful third-party risk management program requires much more than technical training.
Most people who reach upper management in information security come from technical backgrounds, giving them a different skill set than their business-school educated colleagues. This culture gap may seem trivial, but it can present real challenges to effectively communicating the vital nature of IT initiatives like TPRM.
Without excellent interdepartmental communication, personnel management, and other so-called “soft skills,” it can be difficult for cybersecurity leaders to secure buy-in from the C-suite, the Board, and, importantly, vendors and partners.
To adapt, many cyber risk professionals are skipping technical certifications and seeking out business or management bonafides, taking leadership seminars and even MBA classes that will help them gain the soft skills necessary for security today.
A number of personal factors go into deciding whether to develop your technical skills or invest in soft skills. Before pursuing a TPRM certification, take a step back and see what will benefit you and your team the most.
Which technical TPRM certifications are the most valuable?
There are a number of TPRM certifications available to security and risk personnel who want to bolster their professional qualifications. Four valuable ones include:
Shared Assessments CTPRP Program
The Certified Third Party Risk Professional (CTPRP) designation from Shared Assessments is intended for professionals in various procurement and compliance roles, including vendor IT security managers, IT auditors/assessors, IS auditors, and more. This certification validates a professional’s knowledge, experience, and credibility as a third-party risk expert. It can also help improve your overall marketability as a TPRM expert.
In order to apply, you must have five years’ experience in a risk management professional capacity.
Details:
Costs:Workshop & Exam: Private, instructor-led classes and volume discounts are available. See the Shared Assessments CTPRP website for more information. |