Vendor and supply chain management covers the processes organizations use to evaluate, onboard, and oversee the external providers that supply hardware, software, and services. Understanding the full supply chain—and the risks embedded within it—is essential for maintaining security and operational continuity.
Vendor & Supply Chain Management
A company usually is working with a lot of different vendors and suppliers, and so that's another area that we need to focus on and have some processes around: selecting the right vendors and making correctly. Vendors could include software providers, hardware providers or service providers.
There is some overlap between asset management and vendor management, and that is that we have to purchase assets from a vendor. So what does that look like? Well, we need to choose the right assets. So if we're choosing a laptop, we need to choose the right assets and make sure we're managing the life cycle of that. But we're purchasing that laptop from a vendor, and so that vendor management does look different. And even if I'm buying a Dell laptop, I'm not necessarily buying it directly from Dell — I could be going through a third party to buy that laptop. Which brings us to the next point: when we're evaluating a vendor, we need to consider the full supply chain.
But what is a supply chain? A supply chain is all the products and services that go into delivering a product or a service. Let me give you an example of this. One of the vendors that I would use for purchasing hardware was CDW, and I would purchase Dell laptops from CDW. Two different products here, two different companies here. And Dell buys the components for their laptop from other people, so you have some sort of battery that's a completely different brand, a different company, that goes into the Dell laptop. But those people that produce the battery need to get the raw materials from somewhere. And this is a very oversimplification — there's shipping that happens between all of these, there's other products that get created as it steps up through all of this process. So this is the full supply chain.
And there are a lot of vulnerabilities within this supply chain. So for instance, there could be shortages. If we have a shortage of raw material, that's going to affect how much batteries that can be produced, which is going to affect how many laptops can be created, which is going to affect how many laptops CDW can sell.
Or there could be changes along the way. There could be manufacturing changes. I've seen where bad batteries have gotten into Dell and Macs and Lenovo and all sorts of brands of laptops, because they were all sourced from a same source, and so there were problems with that.
Or we could see delays along the way, where there is delays in shipping. Or we could see some security issues: there could be attacks that could happen where products have some sort of vulnerabilities with them and gets passed on to us, the consumer.
And it's not just with hardware as well. There's a lot of different managed services that are out there, whether it be services that are up in the cloud, or perhaps it's your internet service provider. Here's an example. I had a great experience with an internet service provider. We did an evaluation of this vendor for phone services, to get our phone services through them, and it turned out terrible. We signed this contract and they just couldn't deliver on the contract. It was really bad performance on their part.
There are also things like mobile service providers. And one of the things that I would do — and this is becoming more and more popular — is outsourcing things like help desk. And so that is a managed service as well, and choosing the right vendors for that.
So when it comes to vendor management, there's a life cycle to it. And I also threw in here partner management too, because we need to think about partnerships in the same way: we're delivering services to each other when it comes to partnerships.
So what does that look like? Well, first of all, we're going to have some sort of needs assessment that we're going to do to figure out what the business need is. Then we'll go through a vendor assessment on what vendors meet that need. Although I can tell you, I've seen a lot of times — usually not the IT department, but it's other departments — that jump straight into a solution, some sort of choosing a vendor or a product that's going to, what they think is going to, meet their needs, and it doesn't do what they want it to do because they didn't go through a proper needs assessment.
So we need to start at that needs assessment. Then we get into negotiating contracts. We go through an onboarding process to get onboarded with them. We go through management and monitoring to make sure they're delivering the services that they promised. And then there are things that change along the way — usually these services are pretty dynamic and there are changes that happen, so managing those changes. And then at some point in time, or at least a lot of contracts end up with it, you'll have to terminate that contract, and so that would be the termination of this life cycle.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →