Previously the Vendor Management Module, the Third Party Management Module ensures the proper risk management of your most important vendors. In this shared responsibility approach, your vCISO Specialist will work with someone on your staff to set up your Vendor Management Program. This includes templates and basic training. Your vCISO Specialist will provide ongoing support of the program and will also perform IS due diligence reviews for up to 7 existing critical vendors each year. You’ll also get due diligence reviews for up to 3 new vendors each year if you ever need to make a change. The entire program is summarized and reported to the board annually.
Deliverables:
- Establish the Third-Party Risk Management Program, including Policy, Risk Thresholds, Tracking Sheets, Requests Lists, Review Checklists, Etc. (for internal use)
- SOC2 reviews for up to 7 Critical Third Parties
- Review up to 7 Critical Third Party Contracts for GLBA requirements***
- Third Party Management Board Report
Optional:
- Additional Critical Third Party SOC2 (or questionnaire) review
- Additional GLBA Contract reviews ***
***We are not lawyers and cannot provide legal advice. Contract Reviews are meant to assess the regulatory compliance of a contract only and should be a part of your larger contract review process, including legal review by your lawyer.