← Back to GRC Projects

PROJECT 04 / THIRD-PARTY RISK

Third-Party Cybersecurity Risk Assessment

A simulated third-party risk management assessment evaluating a cloud-based vendor's business criticality, data exposure, system connectivity, cybersecurity controls, due diligence evidence, identified gaps, residual risk, and required remediation.

VENDOR Northstar Cloud Services
SERVICE SaaS Platform
VENDOR TIER Tier 1 / Critical
DECISION Conditional Approval

01 / EXECUTIVE SUMMARY

Vendor risk overview.

Northstar Cloud Services is a fictional SaaS provider being evaluated before onboarding by a simulated organization.

The service would support an important business process, process confidential organizational information, maintain user accounts, and integrate with the organization's identity environment.

Because the vendor would handle sensitive information and support an important business function, the relationship is classified as Tier 1 / Critical and requires enhanced cybersecurity due diligence before approval.

The assessment identified several strong controls, including multifactor authentication, encryption, centralized logging, vulnerability scanning, and documented incident response procedures.

However, gaps were identified in privileged access governance, recovery testing evidence, subcontractor oversight, and incident notification requirements.

All vendor information, findings, evidence, and assessment results used in this project are simulated.

02 / VENDOR PROFILE

Understanding the relationship.

Third-party risk begins with understanding what the vendor does, what information it can access, how it connects to the organization, and what would happen if the service became unavailable or compromised.

01 Business Service

Cloud-hosted SaaS platform supporting an important internal business process.

02 Data Classification

Confidential business information and employee-related information.

03 Authentication

Federated organizational identities with role-based user access.

04 Connectivity

Internet-based SaaS access with approved application integrations.

05 Availability

Service disruption could negatively affect normal business operations.

06 Subprocessors

Vendor relies on additional cloud and service providers to deliver portions of the service.

03 / INHERENT RISK

Risk before controls.

Inherent vendor risk considers the exposure created by the relationship before evaluating the effectiveness of the vendor's security controls.

Data Sensitivity 5
Business Criticality 4
System Access 4
Availability Impact 4
Third-Party Dependency 4
Overall Critical

04 / DUE DILIGENCE

Evidence reviewed.

Vendor claims should be supported by appropriate documentation and evidence before control effectiveness is accepted.

01

Security Questionnaire

Reviewed responses covering governance, IAM, data security, vulnerability management, monitoring, incident response, and resilience.

02

Independent Assurance

Reviewed simulated independent assurance documentation describing security control design and operation.

03

Security Policies

Reviewed access control, vulnerability management, incident response, encryption, and backup policies.

04

Architecture

Reviewed simulated architecture and data-flow documentation to understand system boundaries and integrations.

05

Resilience Evidence

Reviewed backup, recovery, continuity, and restoration testing documentation.

06

Contract Requirements

Reviewed cybersecurity obligations, breach notification language, data handling, and subcontractor requirements.

05 / CONTROL ASSESSMENT

Vendor security controls.

Representative controls were evaluated using questionnaire responses and simulated supporting evidence.

Domain Control Evidence Assessment Risk
Governance Documented information security program Security policy and governance documentation Effective Low
IAM MFA for workforce and administrative access Authentication configuration and policy Effective Low
IAM Privileged access reviews performed on a defined cadence Incomplete review records Partially Effective High
Data Security Encryption of data at rest and in transit Encryption standard and configuration evidence Effective Low
Vulnerability Management Recurring vulnerability scanning and remediation Scan results and remediation process Effective Low
Monitoring Centralized security logging and alerting Logging architecture and monitoring procedures Effective Low
Incident Response Documented incident response process Incident response plan Effective Low
Incident Response Contractual incident notification requirement Contract language lacks defined notification timeframe Deficient High
Resilience Periodic recovery testing Limited restoration testing evidence Partially Effective Medium
Supply Chain Security oversight of critical subprocessors Incomplete evidence of recurring subprocessor review Partially Effective High

06 / FINDINGS

Identified control gaps.

ID Finding Risk Required Action Status
TPR-001 Evidence does not demonstrate consistent recurring privileged access reviews. High Establish quarterly privileged access certification and retain review evidence. Open
TPR-002 Contract does not establish a defined cybersecurity incident notification timeframe. High Add contractual incident notification requirements before production use. Open
TPR-003 Recovery testing evidence does not demonstrate regular full restoration validation. Medium Provide current recovery testing evidence and establish recurring restoration testing. Open
TPR-004 Evidence of recurring security review for critical subprocessors is incomplete. High Establish documented subprocessor security review and monitoring requirements. Open

07 / PRIORITY FINDING

Incident notification requirement.

TPR-002

Undefined Security Incident Notification

HIGH
CONDITION

The simulated vendor contract requires incident notification but does not define a specific notification timeframe.

RISK

Delayed notification could prevent the organization from quickly evaluating exposure, initiating incident response, meeting downstream obligations, or communicating with stakeholders.

DOMAIN

Third-Party Incident Management

SEVERITY

High

OWNER

Vendor Management / Legal

TREATMENT

Mitigate

REQUIRED REMEDIATION
  • Establish a defined security incident notification timeframe.
  • Define the events that trigger notification requirements.
  • Require sufficient information to support organizational incident response.
  • Establish escalation contacts for significant security events.
  • Require ongoing updates during material security incidents.
ACCEPTANCE CRITERIA CONTRACT UPDATE REQUIRED

The vendor may proceed through conditional approval, but the contractual notification requirement must be resolved before the service enters unrestricted production use.

08 / RESIDUAL RISK

Risk after control review.

Existing safeguards reduce the vendor's inherent exposure, but unresolved control gaps leave meaningful residual risk that requires continued treatment and monitoring.

Inherent Risk Critical
Control Strength Moderate
Open Findings 4
High Findings 3
Medium Findings 1
Residual Risk High

09 / RISK DECISION

Conditional approval.

VENDOR DECISION

Approve With Conditions

HIGH RESIDUAL RISK
APPROVAL CONDITIONS
  • Resolve contractual incident notification requirements before unrestricted production use.
  • Provide evidence of recurring privileged access reviews.
  • Provide updated recovery testing evidence.
  • Establish recurring security review requirements for critical subprocessors.
  • Track all open findings through the organization's vendor remediation process.
  • Reassess the vendor following remediation or at the next scheduled Tier 1 review.
DECISION RATIONALE CONDITIONAL APPROVAL

The vendor demonstrates multiple established cybersecurity safeguards, but the remaining findings require formal remediation and monitoring. Approval is therefore conditioned on documented treatment requirements rather than treating the assessment as a simple pass-or-fail exercise.

10 / CONTINUOUS MONITORING

Risk does not end at onboarding.

Critical vendors require ongoing monitoring because security posture, services, subprocessors, business criticality, and threat exposure can change over time.

01

Annual Reassessment

Perform recurring cybersecurity review based on the vendor's criticality and risk tier.

02

Finding Tracking

Track open remediation items, due dates, evidence, and risk acceptance decisions.

03

Material Changes

Reassess when services, data access, integrations, ownership, or hosting arrangements materially change.

04

Security Incidents

Trigger additional review when significant vendor security incidents occur.

05

Assurance Evidence

Obtain updated independent assurance reports and relevant security evidence.

06

Risk Reporting

Escalate overdue findings and material vendor risks to appropriate stakeholders.

11 / GRC TAKEAWAY

What this project demonstrates.

01

Vendor Tiering

Determine assessment depth based on business criticality, data, access, and dependency.

02

Inherent Risk

Evaluate exposure created by the relationship before considering safeguards.

03

Due Diligence

Validate vendor claims using documentation and supporting security evidence.

04

Control Assessment

Identify effective, partially effective, and deficient vendor safeguards.

05

Residual Risk

Determine remaining exposure after existing controls are considered.

06

Risk Treatment

Translate findings into remediation requirements, approval conditions, and ongoing monitoring.

PROJECT CONCLUSION

Vendor trust should be evidence-based.

This project demonstrates how third-party cybersecurity risk can be evaluated through vendor tiering, inherent risk analysis, evidence-based due diligence, control assessment, finding management, residual risk analysis, conditional approval, and continuous monitoring.