Skip to content

Third-party and supply chain assessment

Tiering suppliers, asking questions that produce information, reading audit reports and SBOMs, and contracting for what matters.

Free on glitchdata intermediate 4 lessons 54 min

What you'll learn

  • Tier suppliers by data, dependence and integration depth
  • Replace generic questionnaires with questions and artefacts that inform
  • Read an audit report, a test summary and an SBOM critically
  • Negotiate the contract terms that matter and monitor afterwards

About this course

Most organisations have more exposure through suppliers than through their own infrastructure, and assess it with a questionnaire nobody reads carefully.

This course covers how to tier suppliers by what they can actually cost you, what to ask and what to ask for instead, how to read an audit report or an SBOM, and which contractual terms are worth negotiating.

Before you start

  • Some involvement in procurement or vendor management

Course content

4 lessons · 54 min

  1. 1
    Why suppliers are your attack surface

    Four distinct kinds of third-party exposure, which need four different answers.

    Free preview 13 min
  2. 2
    Tiering, and questions that produce information

    Scaling effort to exposure, and replacing yes-or-no forms with specifics and artefacts.

    14 min
  3. 3
    Reading audit reports, test summaries and SBOMs

    What each artefact actually certifies, and the pages that matter.

    14 min
  4. 4
    Contracts, monitoring and exit

    The clauses worth negotiating, what to watch during the relationship, and leaving without leaving data behind.

    13 min

What learners say

Sign in and enrol to leave a review.

No reviews yet — be the first once you have worked through it.

More in Cyber security