Your glossary for risk and compliance
Helpful definitions of all of the terms you need to know to better manage risk and compliance.
Terms
AFSL Authorised Representative AICPA Annex A Controls ASIC Attestation of Compliance (AOC) Business Continuity Management Compliance Automation Software Compliance Risk Management Cybersecurity Maturity Model Certification (CMMC) FedRAMP Governance Risk & Compliance (GRC) GPDR HIPAA HITRUST Incident Management Information Security Management System (ISMS) ISMS Governing Body ISO 27001 Notifiable Data Breach OAIC Policy Management SOC 1 SOC 2 SOC 3 SOC Reports SOC Trust Services Criteria (TSC) SSAE 16 SSAE 18 Third Party Risk Management Vendor Assessment Vendor Management Policy Vendor Review Vulnerability Vulnerability Management
What is a Vendor Assessment?
Vendor assessment describes an organization's program of assessing its vendors' management of that organization's information, and whether vendors are implementing and maintaining appropriate security controls. A vendor assessment program will establish guidelines to ensure that an organization's vendors comply with that organization's required information security policies and procedures. Vendor assessment is one part of an organization's larger program of maintaining the safety of its internal and customer data and information. Organizations will seek a security review of active and potential vendors, and vendors must demonstrate that they have practices in place to securely manage data.
Implementing a vendor assessment program is a way for an organization to ensure that its varied vendors are consistently compliant with required security policies and procedures.