TechKnowSurge
NIST CSF GV.SC-06 NIST CSF GV.SC-07 NIST CSF GV.SC-10 CompTIA Security+ 5.3 NIST CSF GV.SC-04 NIST CSF ID.AM-02 ISC2 CISSP 1.11
VideoSecurityFree

Vendor Management

Vendor management is a structured lifecycle that covers everything from gathering requirements and assessing vendors to negotiating contracts, onboarding, ongoing monitoring, and eventual contract termination. It applies across hardware, software, and service providers, including managed service providers handling outsourced functions like help desk or security.

Complete this video to capture a CTF flag worth 1 point.

About this video

Vendor management is a structured lifecycle that organizations follow from the moment they begin evaluating potential vendors to the point at which a contract is terminated or a relationship transitions into something new. Rather than reacting to a compelling product demo or a well-timed sales pitch, effective vendor management starts with a disciplined requirements-gathering phase. Defining what the organization actually needs before evaluating specific products or vendors reduces the risk of committing to a solution that falls short during or after implementation. Once requirements are established, vendor and product assessments can be conducted objectively, and a shortlist of qualified candidates can move forward into contract negotiation. After contracts are signed, the onboarding phase begins, with complexity varying significantly depending on whether the engagement involves straightforward software licensing or a large-scale infrastructure project. Ongoing management follows onboarding and includes verifying that vendors are meeting their contractual obligations, processing payments, and monitoring performance. When the scope or nature of the relationship shifts, formal change management processes are applied before resuming standard monitoring. This cycle of managing, adjusting, and monitoring continues throughout the life of the relationship until the contract is ultimately terminated, whether that happens after a short engagement or a long-term partnership. This lifecycle applies across the full range of vendor types an organization might work with, including hardware vendors supplying devices and network equipment, software publishers offering commercial or specialty applications, and cloud service providers such as AWS, Azure, or Google Cloud. It also covers managed service providers, which take on ongoing operational responsibilities that were previously handled internally. Common examples include outsourced help desk support, security operations, and network or infrastructure management. Whether an engagement is a time-limited project like a penetration test or a continuous managed service, the same foundational lifecycle principles govern how the relationship is initiated, maintained, and concluded.

What you'll learn

What's covered

Vendor Management

Aligned to

NIST CSF
GV.SC-06 Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships.
GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship.
GV.SC-10 Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or supply chain relationship.
GV.SC-04 Suppliers are known and prioritized by criticality.
ID.AM-02 Inventories of software, services, and systems managed by the organization are maintained.
CompTIA Security+
5.3 Explain the processes associated with third-party risk assessment and management.
ISC2 CISSP
1.11 Apply Supply Chain Risk Management (SCRM) concepts

Key terms

Vendor Management Life Cycle
The end-to-end process of managing vendor relationships from requirements gathering and vendor assessment through onboarding, ongoing monitoring, change management, and contract termination.
Requirements Gathering
The process of identifying and documenting organizational needs before selecting a vendor or product to ensure the solution aligns with business objectives.
Vendor Assessment
The evaluation of potential vendors to determine whether they can meet an organization's defined requirements.
Onboarding
The process of integrating a new employee into an organization, including provisioning system access, assigning permissions, and providing security awareness training.
Change Management
A structured process for requesting, reviewing, approving, and documenting changes to IT systems or organizational procedures. Change management reduces security risk by ensuring modifications are tested and authorized before deployment.
Contract Termination
The formal end of a vendor relationship or agreement, marking the conclusion of the vendor management life cycle.
Managed Service Provider
MSP
A third-party company that remotely manages a customer's IT infrastructure or end-user systems. MSPs can introduce shared security risks; a compromised MSP can serve as a launchpad for attacks against all of its clients simultaneously.
Service Provider
A vendor that delivers a specific service, such as cloud computing or penetration testing, either on a short-term or ongoing basis.
Penetration Testing
An authorized simulated attack on a system to identify and evaluate security vulnerabilities.

Topics

Vendor Management Vendor Lifecycle Third Party Risk Managed Service Providers Contract Negotiation Cybersecurity Governance

Transcript

When it comes to vendor management, it's a life cycle. We're going to manage the beginning, how we're setting up this partnership or setting up this relationship. There's a middle, of managing this relationship. And there's an end to it, a point in time where we are going to terminate this relationship, or it's going to at least change into something else. So we have this life cycle from a vendor management perspective.

It's actually going to be very similar to our asset acquisition and procurement process. The reason why it's very similar is because there are a lot of parallels between assessing products and vendors — we're buying products from a vendor, and so we do need to assess the product, but we also need to assess the vendor as well.

Gathering requirements

What does this look like? First of all, before we even start selecting vendors, we're going to start gathering requirements. All too often, maybe a salesperson reached out to you, or maybe you saw a product demo, or maybe you were at a conference and you saw some sort of product that you really liked, and now we latch on to that product and that's the one that we want to purchase. But we need to think about this from a larger perspective. Is that product really what you need at that time? Is there going to be another product that's going to be better for you? Are you going to get halfway down the road of implementing this product and realize it's not going to do exactly what you want it to do? So assessing the product first is going to be really, really important.

Vendor assessment and contracts

Once we've assessed what our requirements are, what we're trying to achieve, then we get into the vendor assessment. What are the vendors and products out there that are actually going to meet our needs for whatever requirements we gather?

Once we've assessed those vendors, and towards the end of that have selected a few of the vendors or one of those vendors, then we go into negotiating contracts. We've got to have some contracts and agreements, and we're going to have different agreements that we're going to sign or agree to between the two different parties.

Onboarding, management and termination

Once we've done that, there's this onboarding process. If it's simple software, this might be a simple process that we have to go through. If it's a more complex project, then maybe we have to go through a lot more onboarding with this.

Once we've onboarded them, then there's this ongoing managing and monitoring that we have to do of this vendor. We have to pay the vendor, we have to make sure that they're fulfilling their contract agreements, what we agreed upon. So we have this whole management process that we go through.

Often our services with these vendors change, and so there are times when we have to go through change management with these vendors. Once we go through change management, then we come back to more managing and monitoring whatever has changed with that. So there's this kind of cycle that happens between the management and having to go through some change management with these different vendors.

Then at some point in time we're probably going to terminate that contract. Usually relationships don't last forever. Some of them last for a really long time, some of them are a very short period of time, but there is some sort of contract termination at the end of when this partnership or relationship is about to end.

Vendor types

A lot of what we're going to talk about really applies to several different vendor types or product types. What are they selling? Are they selling certain hardware — is it like firewalls or laptops, or maybe some sort of hardware we're implementing on our network? Or is it some sort of software? Maybe it's Microsoft and it's a Microsoft product, or an Adobe product, or maybe it's some sort of specialty software — there's lots of different software out there we could be purchasing. Or maybe it's some sort of service provider, like maybe a cloud service provider, maybe it's AWS or Azure or Google Cloud. So we have these different vendor types.

Managed service providers

Sometimes a service provider is just going to provide a service for a short period of time. Maybe it's a project, we sign some sort of agreement that they're going to come in and provide that service for a short period of time. Maybe it's like pen testing: they're going to do the pen testing, it's then over with, and then the contract has ended.

But sometimes we have ongoing services that they're providing for us. We call this a managed service provider, that they're managing one of the services that traditionally maybe has been internal but now they're managing it for us. One example of that is help desk. One time I hired a company to come in and manage our help desk for us, and then we started routing calls to this help desk provider rather than internally and having somebody internally that would do that for us. So they would provide help desk services for us. That is an example of a managed service provider. They could also be taking over possibly our security, managing our security, or maybe it's our network, or maybe it's our infrastructure.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →