logo

A Vendor Risk Management Workflow for 2024 Cyber Threats | UpGuard

ID: d37838b1-fab8-5bd0-902d-2c6e73b8c507

STIX ID: report--d37838b1-fab8-5bd0-902d-2c6e73b8c507

Feed Name: UpGuard Blog

Date Published: 2024-04-12

Date Updated: 2026-05-01

...
...

**Executive summary:** This document outlines a six-stage Vendor Risk Management (VRM) workflow—identify and inventory all third-party vendors, group critical vendors, determine regulatory impact, conduct initial evidence-driven risk assessments, establish routine reassessments, and implement notification systems—to streamline discovery, assessment, and remediation of third-party security risks; it emphasizes evidence sources (automated scans, questionnaires, public information, and additional artifacts), vendor tiering, automation and integrations (e.g., UpGuard, Jira), and continuous monitoring to reduce exposure from third- and fourth-party attack surfaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.