TechKnowSurge
NIST CSF GV.SC-06 NIST CSF GV.SC-07 NIST CSF GV.SC-10 CompTIA Security+ 5.3 NIST 800-53 SR-2 NIST CSF GV.SC-01 ISC2 CISSP 1.11 NIST NICE K0820
VideoSecurityFree

Vendor and Supply Chain Management

Vendor and supply chain management covers the processes organizations use to evaluate, onboard, and oversee the external providers that supply hardware, software, and services. Understanding the full supply chain—and the risks embedded within it—is essential for maintaining security and operational continuity.

Complete this video to capture a CTF flag worth 1 point.

About this video

Vendor and partner management follows a structured lifecycle designed to reduce these risks. It begins with a thorough needs assessment to define business requirements before any product or provider is evaluated—skipping this step is a common source of failed implementations. From there, the process moves through vendor assessment, contract negotiation, onboarding, and ongoing performance monitoring to confirm that agreed-upon service levels are being met. As business needs evolve, managing changes to vendor relationships is an ongoing responsibility, and the lifecycle concludes with a formal contract termination process when a vendor relationship ends.

What you'll learn

What's covered

Vendor & Supply Chain Management

Aligned to

NIST CSF
GV.SC-06 Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships.
GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship.
GV.SC-10 Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or supply chain relationship.
GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders.
CompTIA Security+
5.3 Explain the processes associated with third-party risk assessment and management.
NIST 800-53
SR-2 Supply Chain Risk Management Plan
ISC2 CISSP
1.11 Apply Supply Chain Risk Management (SCRM) concepts
NIST NICE
K0820 Knowledge of supply chain risks

Key terms

Vendor Management
The process of selecting, contracting, monitoring, and terminating relationships with external suppliers of hardware, software, or services.
Supply Chain
The network of vendors, suppliers, and service providers whose hardware, software, or services an organization depends on, each representing a potential source of security vulnerability.
Needs Assessment
The process of identifying and defining a business requirement before evaluating or selecting a vendor or solution.
Vendor Assessment
The evaluation of potential vendors to determine whether they can meet an organization's defined requirements.
Managed Service
An outsourced IT function or business process delivered by a third-party provider under a contractual agreement.
Risk
The potential for loss or harm resulting from a threat exploiting a vulnerability.
Vulnerability
A weakness in a system, application, or process that can be exploited by a threat actor.

Topics

Vendor Management Supply Chain Security Third Party Risk Procurement Security Contract Management Cybersecurity Governance

Transcript

A company usually is working with a lot of different vendors and suppliers, and so that's another area that we need to focus on and have some processes around: selecting the right vendors and making correctly. Vendors could include software providers, hardware providers or service providers.

There is some overlap between asset management and vendor management, and that is that we have to purchase assets from a vendor. So what does that look like? Well, we need to choose the right assets. So if we're choosing a laptop, we need to choose the right assets and make sure we're managing the life cycle of that. But we're purchasing that laptop from a vendor, and so that vendor management does look different. And even if I'm buying a Dell laptop, I'm not necessarily buying it directly from Dell — I could be going through a third party to buy that laptop. Which brings us to the next point: when we're evaluating a vendor, we need to consider the full supply chain.

What a supply chain is

But what is a supply chain? A supply chain is all the products and services that go into delivering a product or a service. Let me give you an example of this. One of the vendors that I would use for purchasing hardware was CDW, and I would purchase Dell laptops from CDW. Two different products here, two different companies here. And Dell buys the components for their laptop from other people, so you have some sort of battery that's a completely different brand, a different company, that goes into the Dell laptop. But those people that produce the battery need to get the raw materials from somewhere. And this is a very oversimplification — there's shipping that happens between all of these, there's other products that get created as it steps up through all of this process. So this is the full supply chain.

Vulnerabilities in the supply chain

And there are a lot of vulnerabilities within this supply chain. So for instance, there could be shortages. If we have a shortage of raw material, that's going to affect how much batteries that can be produced, which is going to affect how many laptops can be created, which is going to affect how many laptops CDW can sell.

Or there could be changes along the way. There could be manufacturing changes. I've seen where bad batteries have gotten into Dell and Macs and Lenovo and all sorts of brands of laptops, because they were all sourced from a same source, and so there were problems with that.

Or we could see delays along the way, where there is delays in shipping. Or we could see some security issues: there could be attacks that could happen where products have some sort of vulnerabilities with them and gets passed on to us, the consumer.

And it's not just with hardware as well. There's a lot of different managed services that are out there, whether it be services that are up in the cloud, or perhaps it's your internet service provider. Here's an example. I had a great experience with an internet service provider. We did an evaluation of this vendor for phone services, to get our phone services through them, and it turned out terrible. We signed this contract and they just couldn't deliver on the contract. It was really bad performance on their part.

There are also things like mobile service providers. And one of the things that I would do — and this is becoming more and more popular — is outsourcing things like help desk. And so that is a managed service as well, and choosing the right vendors for that.

The vendor management life cycle

So when it comes to vendor management, there's a life cycle to it. And I also threw in here partner management too, because we need to think about partnerships in the same way: we're delivering services to each other when it comes to partnerships.

So what does that look like? Well, first of all, we're going to have some sort of needs assessment that we're going to do to figure out what the business need is. Then we'll go through a vendor assessment on what vendors meet that need. Although I can tell you, I've seen a lot of times — usually not the IT department, but it's other departments — that jump straight into a solution, some sort of choosing a vendor or a product that's going to, what they think is going to, meet their needs, and it doesn't do what they want it to do because they didn't go through a proper needs assessment.

So we need to start at that needs assessment. Then we get into negotiating contracts. We go through an onboarding process to get onboarded with them. We go through management and monitoring to make sure they're delivering the services that they promised. And then there are things that change along the way — usually these services are pretty dynamic and there are changes that happen, so managing those changes. And then at some point in time, or at least a lot of contracts end up with it, you'll have to terminate that contract, and so that would be the termination of this life cycle.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →