Vendor assessment is the structured process of identifying, evaluating, and selecting third-party suppliers based on defined requirements, security criteria, and business fit. Key considerations include scoring methodologies, conflict of interest, vendor lock-in, and independent audits.
Vendor Selection & Assessment
Once we start gathering the requirements, it's time to start looking for vendors that are going to supply that product or service we're looking for, the one that's going to meet our needs, and to start assessing them.
Once we've gathered the requirements for whatever we're trying to accomplish and how we're going to measure our different vendors, then it's time to go into the vendor selection. There are a few things that need to happen with this. First of all, we need to select or search for vendors that are actually going to supply the products and services that we need. Once we have a selection of different vendors, we're going to go into the vendor assessment and assess these vendors. Then once we've done that, we have to select one of the vendors.
If I'm choosing a simple product from a vendor — maybe it's a piece of software that really doesn't cost a lot of money nor time to implement, nor really has a lot of security concerns — I might just go with a vendor and say this is going to be good, implement it, and see how it works. But if this is going to be something that has a significant amount of investment into it, if I'm going to have to invest a lot of transition time to transition over to this software or implement this software, or maybe it's going to have some really sensitive data in it so I need to make sure that security is going to be tight with it, then what I might do in these scenarios is choose multiple vendors. I select a lot of different vendors so that way I can get a better sense of which vendor is going to best meet my needs. If this is a bigger project or a more sensitive project, then I choose at least three vendors to evaluate, sometimes even more. For instance, when I did my phone system for the company, I evaluated seven different vendors to make sure that they were going to meet our needs.
Why would I do this? It does create extra time and effort to assess so many vendors, so you can go overboard and get too much product selection, and then you run into other issues. But the reasons I really find this helpful:
One way I like to assess vendors is by lining up my requirements and then creating a table that I measure for each one of these requirements that I have. Perhaps I could do it by a scale of 0 through 10, so maybe company A rates an eight out of 10, maybe company B is a five out of 10, maybe company C is a s out of 10. They get some sort of rating based off how well they fulfill this requirement.
Another way is what I call forced ranking, and that is: which one is the best. Maybe company B is the best, so they're number one, then company C, so they're number two, and then company A is number three.
Maybe some of your requirements are whether they meet it or not, and maybe that will eliminate some of your options. Company A has this requirement, yes. Company B has this requirement. Company C does not, so it eliminates them from this option.
There are several different ways we could go about evaluating these companies or these vendors to find out which one is going to be the best to meet our requirements.
We may require some sort of independent assessments. Here's an example. I was utilizing AWS's services — it's a cloud provider — and we were moving our whole infrastructure up to AWS. I wanted to make sure that they were going to be able to meet our security concerns, so I pulled their SOC report, a SOC 2 Type II. They were SOC 2 Type II compliant, and there was a report I could pull and analyze to make sure that they would meet our security requirements. It was a resounding yes. AWS has a whole security team and makes sure that they're doing things right. But this was an independent assessment of AWS: a third party, an outside party that specializes in those types of reports.
Let me give you one more example. We were looking at a company — actually, the company was going to acquire the organization that I was working with, so they were going to purchase the company. They hired a third party to come in that specializes in acquisitions. An acquisition is when you purchase another company, so that's what they specialized in, and they could analyze us. I'd have to turn over all sorts of reports to show what we were doing and how we were doing it. So it was a way to make sure that this purchase of this company was going to meet the requirements that are needed, by an independent third-party assessor who specializes in that.
A big part of this might be questionnaires. As an IT director, I got a lot of organizations, a lot of clients, that would send these questionnaires to us, and what we'd have to do is fill out these questionnaires. They were security questionnaires: how do you treat this, what process do you have for this, what do you do for this. There would be yes/no questions, there would be fill-in-the-blank questions, there would be turn-over-your-system-diagrams questions. There would be a lot of questions on this questionnaire about your environment and whether you're going to meet the requirements that this client had. One of my jobs was to take these questionnaires and fill them out for our clients, for our customers, so that way we could get their business.
What you could do is develop your own questionnaire, or there are questionnaires out there that you could require your vendors to fill out if you're going to do business with them as part of the assessment process.
We may have a requirement to perform some sort of test. It might be done by a third party, somebody outside that is going to take a look, and that's really common to do — have a third party do something like pen testing that's going to test the network to see how well it is and make sure that it meets certain requirements. But we also may just ask them to have some sort of proof of internal audits, that they turn over their records showing that they've been doing auditing on a regular basis.
Another thing that we could be assessing is any kind of conflict of interest. An interest is something that we desire, something that could be beneficial to us. So let's say we've got a target here and it's beneficial, and in conflict would mean that they don't line up. There could be times when the objectives of our company or organization don't line up with the objectives or interests of another company that we want to do business with, and this is considered a conflict of interest.
Let's look at some examples of conflict of interest. One would be a credit card company who's giving financial advice. They could be giving unwise financial advice to the wrong person because they want them to spend money on a credit card, and this could be unwise in their scenario. So this would be an example where they have an interest in you spending money on a credit card, and that's something that's in conflict with wise financial advice.
Most companies have some sort of rule that somebody that is related to you can't work underneath you. For example, I couldn't hire my son to be underneath me, because I could promote him above everybody else. That's a conflict of interest. The interest is that I want my son to succeed, and it's a conflict because I'm in a position within the company to promote him above other people and to create that success for him.
With a vendor that we're working with, maybe they're providing some sort of services, and part of that service is that they may evaluate our needs to determine if we need that service that they're selling. That's a conflict of interest, because they have a vested interest in the report saying yes, you do need these services, and they also want to sell you those services.
As you can see, there's a wide range of definitions or examples of how conflict of interest applies. What we need to do is evaluate these companies to see if there's a conflict of interest in the services that they're providing for us, or perhaps in the way we are going to set up the agreements, and just make sure that there is no conflict of interest when we're assessing the company.
Another thing we should assess here is: are we going to get vendor locked? That is, are we going to get stuck using a service that maybe we don't want to use in the future? Let me give you an example here. AWS, Azure and Google all have cloud services. There are certain services that I could set up in AWS, and then if I decide later on that I don't like them, I can move to Azure or move to Google. But there are other services that I could build my whole infrastructure based off of being in AWS. Now if for some reason I stop liking their services, or I like some other service better, it could be very difficult or very costly for me to move to another service. So we need to watch out for vendor lock-in: with whatever we're purchasing, are we going to get vendor lock-in, and is that going to be detrimental to us in the future?
There's also vendor lockout, which is a very different principle. This is if we are going to somehow lose connection to what we have in the cloud. In this example right here, we have maybe some of our documents, maybe we have some software, we have other data that's up here in the cloud, and maybe we forget to pay our bill. If we forget to pay our bill, suddenly the cloud provider says you don't get access to your stuff, and that could be very detrimental. In my experience, any of the more professional cloud service providers give you lots of leeway with paying your bill and make sure that they don't lock you out of your services. But there could be services out there that this could be a real danger with — if you skip a payment and suddenly now you don't have access to that service, that could be detrimental to your business.
There are also some concerns when two different industries decide to partner together. Sometimes two companies from two different industries decide let's do business together, or let's merge, or let's work together, and there are some interesting security concerns that can arise from that, because there are two different sets of compliance and laws and regulations.
Let me give you an example of that. Back in the '90s there were a lot of communication systems, phone systems, and they had lots of laws and regulations around these phone systems. Well, they repealed a lot of those laws and regulations to kind of open up the market and let a bunch of other new players come in, and one of the players that came in were the power companies. They already had power lines running everywhere, so it was easy for them to set up communication lines. This doesn't necessarily mean that they shouldn't do both of those, it's just a consideration, because the laws and regulations that power both of these two industries could look quite a bit different, and you need to make sure that those merge successfully.
Ultimately, the goal of gathering these requirements and doing a proper vendor assessment is really to make sure that you're making the right decision, and some of these decisions can be huge. Making sure that we do a proper vendor assessment can really save us a lot of time.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →