Thanks for the session. It is going to help me in upcoming Vendor risk assessment program. Since working in ISG, your sessions is helping to upgrade my knowledge
: 38:09 - Not sure usually majority of the firms follow this regime, it doesn't necessarily require to provide training (Security awareness/Phishing Awareness) to vendors by procuring firm or existing clients because it usually will be set as an expectation from procuring firm that vendor finish security awareness training for all the employees or conduct phishing drills at their own cost and preferred manner. During Vendor risk assessment it should be clarified that yes vendor has finished such trainings for all their employees and also conducting drill on regular interval. Conducting training for all the vendors would be exhaustive and troublesome in scoping( thinking on a software provider or service provider) for clients. If gap has been observed then it is marked as mandatory criteria within MSA considering if not followed then vendor will be subject to contract termination.
Creating a TPRM session was good, but the session should have been a bit more uniform and in sequence. The flow should have been like: why, What, How, When, and Where.
may there r few viewers, but everybody got benefited from this session, Thank You bro.
Great session.. thank you for developing practical sessions like this, very helpful.
This was great. Kavita knocked it out the park. I'd like her to discuss how she developed her spreadsheet and going through a detailed demo.
Thanks for the session.
It is going to help me in upcoming Vendor risk assessment program.
Since working in ISG, your sessions is helping to upgrade my knowledge
It was awesome very informative we still feel need more from her.
This was wonderful. Especially those excel sheet templates! Much appreciated 👍
Great thanks Kavitha and Prabh for this wondefful practical session of TPRM.
great session by kavitha and Prabh..expecting many more
great session. efforts for the template are much appreciated
: 38:09 - Not sure usually majority of the firms follow this regime, it doesn't necessarily require to provide training (Security awareness/Phishing Awareness) to vendors by procuring firm or existing clients because it usually will be set as an expectation from procuring firm that vendor finish security awareness training for all the employees or conduct phishing drills at their own cost and preferred manner. During Vendor risk assessment it should be clarified that yes vendor has finished such trainings for all their employees and also conducting drill on regular interval. Conducting training for all the vendors would be exhaustive and troublesome in scoping( thinking on a software provider or service provider) for clients. If gap has been observed then it is marked as mandatory criteria within MSA considering if not followed then vendor will be subject to contract termination.
It applies to contractors usually where he/she needs to comply with all the specific compliance criteria of the firm.
Great Explanation! Thank a lot for your videos!
Very great session.
Is there any chance to get a copy of the "Risk Assessment and risk treatment report" template?
Thanks Prabu Nair and Kavitha had good session
Hi prabh and Kavitha, will it be possible to share an Excel sheet that you have explained in this video
Yeah that was Good one. Thank you
Very nice session plz share the excel sheet for the viewers thanks.
She made this very simple
Really a great session. Thankyou both Kavitha and Prabh
It’s really a great session with practice approach, thank you both Prabh and Kavitha
Hi Prabhu’s, can we get the excel template for reference
Creating a TPRM session was good, but the session should have been a bit more uniform and in sequence. The flow should have been like: why, What, How, When, and Where.
How we can get this excel sheet
Very informative session 👏
Can we assess and validate a vendor by their SOC 2 type 2 report?
Yes, ensuring that SOC2 report is most recent one within the year and if not then you may ask for Bridge Letter.
Can you provide the name of the certification one should be doing for starting career in TPRM
Can share the Excel sheet
Hi, prabh please can u do the user access review with practical and cryptography audit also network security
For TPRM , is there an ISO standard or so that is particularly for it? Thanks
There’s NIST 800-30
You can look into ISO 31000 ans 27005
Can we get the excel sheet plz Prabh sir ?
This is a great session Kavitha and Prabh ! This is gold - @kavitha can I ping you if I have doubts. Thank you