TPRM-Driven Supply Chain Cybersecurity
Connecting TPRM and supply chain security for operational resilience
Häftad, Engelska, 2026
749 kr
Beställningsvara. Skickas inom 5-8 vardagar. Fri frakt för medlemmar vid köp för minst 249 kr.
Integrate cybersecurity into TPRM to reduce vendor breach impact, meet DORA and NIST C-SCRM expectations, and monitor fourth-party exposure using SBOM-driven diligence, threat intelligence, and automation.Key FeaturesDesign a lifecycle-based TPRM program that ties vendor decisions to cyber riskMap DORA, NIST C-SCRM, and ISO/IEC 27036 controls to audits and evidenceBuild contract clauses, SBOM requirements, and playbooks for third- and fourth-party breachesIncludes assessment templates, evidence checklists, and incident playbooks you can adaptBook DescriptionReduce supply chain cyber risk by turning third-party risk management into an operational program that connects procurement, legal, and security decisions. This book replaces checkbox assessments with a lifecycle approach you can apply from onboarding through offboarding, so vendor risk tiering, control mapping, and continuous monitoring drive clear outcomes.You learn how to align supplier oversight with major obligations and guidance, including DORA, GDPR, Executive Order 14028, NIST C-SCRM, and ISO/IEC 27036. You also get practical methods for strengthening contracts and SLAs—covering audit rights, breach notification, liability, and security requirements that flow down to critical subcontractors.From threat intelligence and security ratings to incident response playbooks for vendor and sub-vendor breaches, the book shows how to handle real signals, not just survey answers. Written by practitioners with deep experience in supply chain risk and offensive security, it also explains how SBOM standards and AI-assisted scoring can support scalable governance. By the end, you can build and mature an intelligence-driven TPRM program focused on measurable resilience.What you will learnLearn how vendor ecosystems become attack pathsCategorize third- and fourth-party supply chain risksCreate risk tiers and segmentation based on business impactDesign a lifecycle workflow from onboarding to offboardingSelect controls using NIST and ISO supply chain guidanceTranslate DORA, GDPR, and EO 14028 duties into controlsPrepare evidence packs for audits and regulator questionsPlan continuous monitoring beyond annual questionnairesWho this book is forThis book is for cybersecurity leaders, TPRM/VRM practitioners, risk managers, and procurement professionals who need a repeatable way to evaluate and monitor vendors and critical suppliers. Compliance teams and in-house counsel working with DORA, GDPR, HIPAA, and related requirements will also benefit. Basic familiarity with security principles and vendor management helps.
Produktinformation
- Utgivningsdatum2026-05-29
- Mått191 x 235 x 19 mm
- Vikt640 g
- FormatHäftad
- SpråkEngelska
- Antal sidor342
- FörlagPackt Publishing Limited
- ISBN9781806708116