Skip to main content

Third-Party Risk Assessment

A vendor review workflow covering due diligence, control questions, risk scoring, and onboarding recommendations.

Organization
Cybersecurity Internship Portfolio
Duration
2 weeks
Project Type
Vendor Risk
NIST CSFISO 27001CIS Controls

Objective

Evaluate third-party vendors and suppliers for cybersecurity risk.

NIST CSFISO 27001CIS Controls

Step-by-Step Execution

  1. Step 1

    Vendor Identification

    • Identified vendors and suppliers requiring cybersecurity review.
  2. Step 2

    Questionnaire Development

    • Developed questionnaire content based on ISO 27001 and NIST CSF.
  3. Step 3

    Vendor Documentation Review

    • Reviewed supporting documentation such as SOC reports and security certifications.
  4. Step 4

    Vendor Risk Scoring

    • Classified vendors as Low, Medium, or High risk.
  5. Step 5

    Recommendations

    • Documented contractual controls, remediation requests, and ongoing monitoring recommendations.

Deliverables

Third-Party Risk

Third-Party Risk Assessment Report

Formal report summarizing vendor risk findings and security review outcomes.

Supports vendor risk decisions and follow-up planning.

Risk Scoring

Vendor Rating Matrix

Matrix classifying vendors as Low, Medium, or High risk.

Creates consistent vendor comparison criteria.

Vendor Governance

Vendor Onboarding & Monitoring Framework

Framework for onboarding vendors, requesting remediation, and monitoring ongoing risk.

Improves third-party governance over the vendor lifecycle.

Skills & Insights Gained

Vendor risk managementThird-party security reviewsSupply chain securityContractual security requirements

Continue exploring

Governance

Governance Policy Development

A structured policy development engagement aligning security expectations with business objectives and recognized frameworks.

ISO 27001NIST CSFCIS Controls
View case study

Internal Audit

Internal Cybersecurity Audit

An internal assessment that reviewed security controls, documented gaps, and produced a prioritized remediation roadmap.

NIST CSFCIS ControlsISO 27001
View case study

Risk Management

Enterprise Risk Assessment

A risk assessment project documenting assets, threats, likelihood, impact, and treatment options for management review.

CIS RAMNIST CSFISO 27001
View case study