CISSP Cyber Training Podcast - CISSP Training Program

CCT 364: Third Party Risk Management - How One Vendor Breach Exposed 119,000 Users

Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur Season 3 Episode 364

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 46:08

Send us Fan Mail

A breach can hit your headlines even when your own systems never get touched, and that’s exactly why third-party risk management keeps showing up on the CISSP exam and in real incident reports. We walk through the Vimeo breach tied to its analytics vendor Anodot, where compromised vendor access and authentication tokens gave attackers a clean path to customer data. No video content or payment data was taken, but names, emails, and metadata exposure is still a trust and reputation problem that security teams have to own.

From there, we zoom out to the bigger pattern behind modern supply chain security: attackers increasingly go after dependencies, CI/CD pipelines, shared developer tools, and widely used vendors because one compromise can cascade across hundreds of customers. We talk about how to reduce that exposure with a stronger TPRM program, including vendor risk tiering, continuous monitoring, SBOM thinking, and practical contractual controls like breach notification timelines, right to audit language, and clear subcontractor disclosure with flow-down requirements to address fourth-party risk.

We also shift into CISSP Domain 1 rapid review mode: what the exam really wants when it asks about due diligence, evidence, and proportional risk decisions. You’ll hear clean explanations of SOC 2 Type 1 vs SOC 2 Type 2, where ISO 27001 fits, why questionnaires like SIG are not proof, and which frameworks matter for third-party and supply chain risk management including NIST 800-161, ISO 27036, and NIST CSF 2.0. We close with practice scenarios that mirror common CISSP traps so you can spot them fast.

Subscribe for more CISSP training, share this with a study partner, and leave a review so more security pros can find the show.

Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.

Join now and start your journey toward CISSP mastery today!

Welcome And Why TPRM Matters

SPEAKER_00

Welcome to the CISSP Cyber Training Podcast, where we provide you the training and tools you need to pass the CISSP exam the first time. Hi, my name is Sean Gerber. I'm your host for this Action Packed Informative Podcast. Join me each week as I provide the information you need to pass the CISSP exam and grow your cybersecurity knowledge. Alright, let's get started.

SPEAKER_01

Good morning, everybody. It's Sean Gerber with CISSP Cyber Training and hope you all are having a beautifully blessed day today. Today's Monday, and we are going to be getting into various aspects related to the CISSP exam, tied today specifically around domain one. And that is TPRM, third-party risk management. Now, if you've been paying any attention in the news, you know that third-party risk management is a huge factor for any organization. And if you are an organization that outsources any of your activities, this comes down from development to any sort of manufacturing pieces to whatever it might be. If you're doing third-party risk or third parties in your organization, you need to understand your third-party risk to your company. So this we're going to get into the various aspects.

CISSP Sprint Cohort And Goals

SPEAKER_01

So I've got an article that's going to come out around Vimeo. We'll talk about that. And then we're going to get into the third-party risk management talk about as far as some training that's available to you. But before we do, wanted to have a real quick, just super quick shout out to our CISSP cohort. So my CISSP cohort is right now the first one's been going on and it's amazing. Things are going great. We're like week five into our eight-week cohort. The pert of it I'm trying to bring forward is the fact that if you want to get your CISSP as short a period of time as possible, eight weeks, go check out my CISSP cohort. It is for you. It's a way we can get you in the process, get your CISSP done, get you trained and ready to go so that in eight weeks, you are ready to take this exam and move on with your life. So go check it out. The CISSP Sprint Cohort at CISSP Cyber Training.

Vimeo Anodot Breach Case Study

SPEAKER_01

So let's talk about a breach that just hit the headlines not too long ago. And this is the perfect case to study for third-party risk management. So if you see the article, as I got it posted on my screen, or if you're just listening to this, it's Vimeo Confirms Breach via third-party vendor that impacts 120,000 people. Actually, 119, but let's just go 120,000. And Vimeo's old systems were never ever touched. So let's talk about that for a minute. What do you think? So Vimeo uses a vendor called An ODot, A-N-O-D-O-T. It's an analytics platform, right? So Anodot got compromised. They were compromised by somebody else. And so Vimeo wasn't compromised. It was their third-party SaaS provider, Anodot. But because Anodot had standing access to Vimeo's data, the attacker walked right through that connection using a compromised authentication tokens from the vendor's relationship. And we talk about this a lot at CISP Cyber Training. Your overall vendor relationships you have with your SaaS providers are your Achilles heel. They're very valuable, right? And you need them to be able to operate. But if you don't have a good platform in place or a good third-party risk management program in place, this can be a problem. So what exactly got exposed? The video titles, the technical metadata, and 119 email addresses. Some paired with specific names. Now, as we all know, we're like, okay, well, that happens all the time. But if you're a business and you're running this, this is not something you really want to just kind of brush off and say, well, that's okay. Everybody, it happens to everybody. Well, so no video content was compromised. No passwords, no payment data, but still 119 people's information was taken out into the wild. And what a bigger problem with this is, is we all deal with the overall aspects of our email addresses have been compromised. The biggest problem is now is that what kind of a black eye does this leave for Vimeo? You've been hacked. Now how does that affect you? So now if you're gonna put your data out there, you're gonna go, well, is their security up to par? You just don't really know. So here's the group behind it. It's Shiny Hunters, a known extortion crew. They've done this a long time. Their playbook is simple, right? Pay or leak. They listed Vimeo on their extortion portal and they published hundreds of gigabytes of data. So when the pressure didn't get them what they wanted, they went and just launched it all, right? That's what they want. But notice something important. The Shiny Hunters didn't breach Vimeo, they breached their vendor. So this is a third-party risk in its purest form, and vendors' access often disindistinguishable from the internal access because they're so embedded within your organization. Your third-party security posture is only as strong as your weakest vendor with access to your data. So this isn't an isolated situation. And here's the part that you really should get your attention. Vimeo is not a one-off, right? In 2026, it has been loaded, has already, and it's like seven months in. Well, no, it's actually more than eight months in, has been loaded with supply chain attacks just like these. Tan Stack was a malicious version of trusted packages, hit OpenAI and Grafana. Stolen GitHub credentials, cloud secrets, SSH keys, and CICD tokens. The GitHub Megalodon campaign, which over 5,500 repositories were compromised, again, another third-party risk situation. This was done through commits disguised as routine automation. Thousands hit within hours. The NX Console extension, a trojanized developer tool that gave attackers a path into the CICD pipelines and production environments. And then even Trellix, a cybersecurity vendor, had its own source code compromised. No organization is immune. We talk about this all the time. It's not a matter of if, it's a matter of when. So these are five major incidents, one common thread. Attackers aren't going through the front door anymore, they're going through the vendors, your dependencies, and your build pipelines. So back to Vimeo. What exactly occurred? So the compromise happened in April of 2026. Vimeo didn't disclose it publicly until May of 5th, 2026. Again, I talk about this when I

2026 Supply Chain Attack Pattern

SPEAKER_01

interview folks and I actually do some consulting work. You need to have a really good incident response plan in place to deal with this situation. Because the last thing you want to do is spend hours upon hours upon hours thinking about how to respond to these situations. If you have a playbook, even though you don't particularly use it the right way, you have a playbook, so therefore you can pivot off of that. Highly recommend you have an incident response plan. And we'll have a couple more videos and audio slash podcasts will be coming out about that here in the coming weeks. So the gap matters. Every day between a compromise and a disclosure is the day your customers don't know if their data may be exposed. So Vimeo's credit, once they moved, they moved quickly. They disabled ANDOT's access, pulled the integration entirely, brought in external experts, and then notified law enforcement. So again, part of an incident response playbook. You better have it all together. But the exposure windows already existed, and that's part how a strong TPRM program is supposed to help shrink this or potentially prevent it altogether. And this is one thing as you have more third parties, you really truly need to have a good program in your organization to deal with this. So what should have been in place before this happened at Vimeo? And that every company then this list that I just provided to you. So vendor risk tiering. It's an important part. A vendor with outstanding access to your customer data is what they would call a tier one or a critical risk vendor. That means a full due diligence, continuous monitoring, and not a one-time questionnaire at onboarding. These tiers are an important part. And I was just talking to a startup just the other day, and they were like, oh, I didn't really think about that. So it's an important aspect that you need to be context contextually and understandingly aware of what's going on. Next one is contractual controls, a fast breach notification clause. So you hear about the problem at your vendor within hours, not weeks. That's the point. You want to know quickly that there's been a problem. And so that you can actually deal with it and address it in a timely manner. Continuous monitoring. Watch a vendor's external posture in real time between your formal reassessments that you may be having. This is something that you would put in and then you would keep an eye on them on a routine basis. And now in 2026, the software supply chain controls too. S bombs, right? Code signing, violations, validations, treating every dependency, plugin, and repository as part of your attack surface. Because it is. You're dealing with these, especially as you get more in the development world and you incorporate AI. You need to have a good understanding of these third parties. Because guess what? These third parties are using AI, like we've mentioned multiple times within their stack. So you need to be aware of that and you need to have a good plan to deal with it. So none of this guarantees a vendor will never get breached. We talk about that. It's not a matter of if, it's a matter of when. But it does shrink the blast radius that if something bad were to happen and it shrinks the time between the compromise and the response. So I'll give you an example. This is kind of a different example that is or is not relatable. When I was drop flying B-1s, we used to have a situation where we would be dropping bombs, and we call these guys the snake eaters. And snake eaters are those forward observers, forward air controllers that are calling in weapons to you. Now they can be Air Force personnel, they can be militar or Marines, they can be pretty much anybody, but they would call in airstrikes. And so these guys are on the ground calling in what you want to do. Now, just as you're aware, that doesn't have to happen. There doesn't have to be somebody on the ground. But in this case, there was. And so this person's down there calling in strikes. So we're dropping in this 2,000-pound bomb, dropping this bomb off of a B1, and we're going like a bat out of heck. And the doors open, we release the bomb. The plane just jostles, right? It just flops. You can feel it just move like a dunk. And you feel the whole plane go up like you're in an elevator. And then you just turn and you see this bomb spiraling down as it's heading towards the earth. And you hear these guys, they just gave you a nine-line and they're telling you where they wanted this bomb to go. And then the bomb hits, and you see this mushroom cloud come up, and it's just, it's impressive. Even for 2,000 pounds, it's just an impressive sight to see. But what's so cool is you hear the person on the radio going, woo-hoo, they're just screaming because they thought that was so, so awesome. And you can hear the air blasting through the radio. So that's a blast radius, right? They were outside of the blast radius. But the point of that was the fact that as it hit and it went off, they could feel the concussion come out of it. Your point is that you want us to be dropping a hundred-pound bomb where the blast radius is meh, versus a 2,000-pound bomb where the blast radius is huge. Right? We don't want the huge one. We want the small one. Small ones are tiny. Those are easy to deal with. You want to avoid the big ones. So let's talk about the five, again, recap the five biggest supply and chain tax of 2026. So before we get into our training, we're going to have today, let's get into those. Number one, Tan Stack is also known as Mini Shiha L Hulabin. I don't even know how to say that. Mini Shah H U L U D. So malicious packages hit OpenAI and Graf Fana, stealing GitHub credentials and the cloud secrets. Number two is the GitHub Megalodon campaign, which we had 5,500 plus repositories compromised in hours. And then number three is the NX Console Extension Compromise, a Trojanized developer tool that opened the door to the CICD pipelines and production systems of numerous organizations and businesses throughout the world. And then number four, the Vimeo and Anadot. This is where 120,000 users had been their exposed through compromise analytics vendors, which we just talked about. And then number five, Trollix, a cybersecurity vendor's own source code breached along with open source tools, trivi, and check marks kicks. So these are five different companies, five different attack paths, one identical root cause, third-party supply chain risk. So here's a takeaway. However, we get into that, right?

Controls That Shrink Blast Radius

SPEAKER_01

We always talk about the event and incidents. Remember that contest, that compost, whatever I'm trying to say, with that little piece, remember incident and event. So the vendor's weaknesses is your breach. It's not the slogan. That's exactly what happened here. And it's exactly what's happened five more times this year alone, just the big ones. We all know that there's many, many, many more out there. So know your vendor tiers, demand real evidence, not just questionnaires. Questionnaires are the easy part. It's actually get the evidence that you need to see. Have the right to audit. That can be in your contractual aspects. So monitor continuously, build your controls before you need them. And that's how you manage third-party risk. So we're going to roll into some training that we've got related to the CISSP. Okay, so we're going to be getting into third-party risk management. But before we do, I did want to bring up one thing: the CISSP Sprint Cohort. I got a new course that's going to be starting again in September. If you listen to this, this is July when they're this recording. But I have Sprint cohorts that are going on on a routine basis. I did my first one and then the process of it, and it's going amazingly well. And I will tell you right now, it I wish, I just truly wish I would have had something like this when I was studying for the CISSP exam. So just think of an expensive boot camp at a fraction of the cost. You get accountability, you get CISSP questions, you get indiv of individual training specifically for you, and you get a diagnostic exam to walk you through where are your strengths and then also where are your weaknesses. I never had any of this. And if you're out there looking at a book, which is great, you're self-studying, this program is for you. If you've got eight weeks and you want to get this done quickly, the CISSP Sprint Cohort is the program. Go check it out at CISSP Cyber Training. It's a banner across the top. There's buttons in there as well. Go check it out, see what it'll give you. We also have other programs that are available for you if that is not what you really want. But if it is something that you want to get at and get going, look at the CISSP Sprint Cohort. Okay, so we're gonna get into third-party risk management. And this is a rapid review with focusing on all the things you need to know for a third-party risk. And so this is an aspect I call that the rapid review because it's gonna go over key things that you're gonna need to know for the exam as well as for a TPRM program within your organization. So there's basically four main buckets that you're gonna be dealing with related to TPRM. The thing you need to understand is due diligence plus contractual controls plus continuous monitoring, those three things equal a TPRM mindset. So we're gonna get into onboarding and due diligence, frameworks and standards, contracts and monitoring, and response and offboarding. These are the life cycle that you need to have for your TPRM plan. This comes down to questionnaires, tiering, the different types of frameworks, could be an ISO, you're talking about right to audit, and then finally breach clauses, access revocation. All

TPRM Lifecycle And Vendor Tiering

SPEAKER_01

of those things will help you build a TPRM program for your organization. So, what the exam will test you? Domain one treats a vendor as an extension of your own risk program. This is a key thing. Every scenario question is testing whether you apply the same rigor to a third party that you would apply internally. So are you looking at them the same way you would do your own environment? Because in today's world, where there's third parties in every aspect of many businesses, from the development space to vendors that are supplying you a service, you need to make sure that you understand the risk that you're incurring by bringing this company or companies on board. So the vendor risk tiers. Not every vendor gets the same review. And I like to talk about this. There's ways you can kind of short circuit or skip around some of this aspect, and we'll get into that in just a minute, but tiers are an important part. So the exam gives you a scenario and asks how much due diligence is appropriate, or whether or not to do it even at all. That's a key factor. They're wanting you to focus on risk. Risk is the huge part in all of this. So tier one is your critical risk. This is where they have access to regulated or sensitive data. That would be a tier one. Or they potentially have direct network or systems integration. In the previous life, I had V people had VPNs, organizations into my organization. That's a direct connection. Now, obviously, that's changed a lot with APIs, but it's still a factor. If you're an organization that's been around for a while, I would be willing to bet you probably have VPNs coming in from an outside entity into your organization. If you have on-site audit plus SOC 2 type two is required, that would be a tier one. Or an annual reassessment minimum. Like they got to be minimally done and reassessed every six months or every year. Minimum. It could be more, right? That would be a tier one type of organization. Tier two would be moderate risk, right? Where you have limited data access, no direct integration. You have a full, you may do the full SIG questionnaire plus an evidence render view of it, but you're not going to the same level as you would do your tier one. You have a biennial reassessment, maybe once every two years you go and talk to them. And then you have continuous security rating monitoring. Now I will say on the tier one aspects, you may not want to do, if they're say a tier one company, and let's say, for example, they go through a SOC 2 type 2 every year. You may have made some changes to your tier one so that you know, because they get certified, SOC 2 type 2, and or maybe their ISO 27001 certified, you decide to go, you know, maybe we won't do an audit of them every year. Maybe we'll do an audit of them every two years or every three years. You have to make that decision. But it's all based on risk. So you may modify these tiers a little bit to meet the needs of the different SaaS providers or different uh third parties that are affecting you or working with you. Tier three is low risk, right? No sensitive data or system access. You might do a questionnaire that's very light or a self-attestation. Basically, send them something and say, just you guys just tell me you're okay. Reassess only during material changes, and it's light touch monitoring. Again, you got to understand your tier different types of third parties that are integrating into you. So, what does the exam test? Tiering happens before any assessment starts. The exam's favorite trap is applying a full onset audit to a low-risk SAS tool. The proportionality to risk, not a one-size-fits-all questionnaire, is the correct answer. You want to have proportionality. You want to be able to use your brain and come up with a risk plan. So when you're dealing with digital evidence, what exactly proves security? So we got type SOC 2, type 2. You have SOC 2, type 1. Each of these are, we'll just kind of go into those real quick. So the type 1 is a point-in-time snapshot only. Controls are designed, but maybe not yet proven operating. Maybe they're operating, but no one's actually gone in to verify the controls are actually there and to ensure that you are doing what you say you're doing. Now, when it rolls into the type 2, this is where an independent auditor tests the controls over the 6 to 12 months. This is considered the gold standard. And many financial organizations will work themselves to a SOC 2 type 2. You have 27,000 one cert. This is where you have a third-party certification. They check the scope and the annex A to controls are actually in place and operational. Your SIG or your SIG Lite, these are standard self-assessment or attestation questionnaires. They're a starting point. They're not proof. They're just saying, hey, are you good? Oh yeah, I'm good. No problem. See, that's the beginning of it, right? It's that it's that relationship you have with your significant other. I like you. You like me. Yes, let's just ask some questions. And as we ask some questions, as we're having a some over a cocktail or over a burger, we then get to realize do we like this person or we do not like this person? And then that moves on to the next thing, right? Or you have a CAIQ, which is your cloud-specific self-assessments and public registry from CSA, the Cloud Security Alliance. This is C A IQ or CSA star. And then finally, you have a pen test summary, which is independent point-in-time technical validation of your overall environment. So these are the digital evidences that are an important part of any TPRM program. So a clean questionnaire is a claim, it's not proof, right? The exam wards pairing self-attested. What does the exam actually test? So they a clean questionnaire is a claim, it's not proof. They are looking for you to have the claim, but then they want the attestation to be validated and backed up with an independently verified evidence. SOC 2, type 2, obviously, pen test, whatever that is. You don't want to rely on it alone. The moment you rely on it alone, guess what? People lie. Yeah, because I I did this when I was in a red teamer. My name was Jessica, and I was very pretty. Yes, and all kinds of air crew loved Jessica because I would talk very nice to them. But if you look at me, if you're on the screen and you're looking at me, you'll go, yeah, you know Jessica. Yeah, I'm not a Jessica by any stretch of the imagination, nor am I attractive by any stretch of the imagination. But hey, on Facebook or on any sort of socials, you can be whatever you want. And now with AI, oh, how much better is it for everyone? So three risk terms in the exam loves to blur third party risk, fourth party risk, and supply chain risk. So the test will test all three, and knowing exactly which one and where the exposure lives is an important part. So third party risk, right? This is risk from your direct vendors and suppliers. This is the relationships you contract and you can audit. These are your third parties. So first party, second party, and third party. Now your fourth party risk kind of goes along the lines of what you already know. This is the risk from your vendors' own vendors. This is the seven layers to Kevin. And bacon and the subcontractors, right? The relationships you don't contract with, and you usually, in most cases, do not see. And the supply chain risk. This is a risk baked into the software, hardware, or components of vendor builds, i.e., a compromised open source package or something along those lines. Something I learned very recently that I did not know. Uh, would the fact that there is, you're dealing with a repo, right? So you're out of CI CD pipeline, and you have folks that are using different types of repositories to pull down open source code. Well, if you have a code base that you're using and you maybe you pull down some open source stuff that has been recently updated, let's just say within the past hour, it's highly recommended do not download that code. They have a cooling off period, basically anywhere from 24 to 48 hours, and maybe even longer, depending on the situation, before you start pulling down code from an open source repository. Good point is the fact is that sometimes bad guys and girls will put the fun stuff in these repositories, and when you download it and put it into your code, you now have just incurred a supply chain risk. Ba-boom. So it's an important part for you to think about. I did not know that. It's a really good piece, and I think that it's important for all of you to keep aware of that. So, what the exam will test, students assume a fourth party risk is someone else's problem, but it's not, right? The Vimeo Anadot breach that we talked about that had 120,000 people were compromised, happened because Anadots, Vimeo's third party, had standing access, and Vimeo's customers became the fourth party victims. So contracts must require subcontract disclosure. The subcontractor needs to say, oh, Houston, we have a problem, and they need to do it quickly. And you

Proof Over Questionnaires SOC2 ISO

SPEAKER_01

that therefore you have the ability to respond or make changes appropriately. So three name frameworks you must know, Cole. NIST 800-161, ISO 27036, and the NIST Cybersecurity Framework 2.0. Okay, so the 800-161, this is a Cybersecurity Supply Chain Risk Management, C S C R M. This is what's used by the U.S. Federal Frameworks and the risk-based lifecycle approach. So you need to understand that if you're dealing with the federal government, you will understand 8161. ISO 27,036, this is where information security suppliers have full lifecycle from the relationship setup through the termination. There's parts one through four, and it will walk you through that. And then in 2024, the cybersecurity uh framework updated their supply chain risk management as its own category under the govern function. So basically, CSF did not have it, it had it as a bullet of its own, but now it has its own category because the risk is so high and so many people are dealing with the problem. So, what the exam tests? Don't collapse these into one vendor risk framework. 800-161 is a U.S. federal guidance. 27,036 is the international supplier relationship. And then cybersecurity framework has its own where governance expectations are now lives. So there's three different bodies, three different scopes. So if they ask you and they kind of come into a question, well, they all fall under one bucket. No, they are all different frameworks specifically designed around third-party risk. So the vendor onboarding workflow, these are six specific stages that you need to be aware of. One is scoping. This defines the requirements and the risk tier before you even get playing with them. Before you go on the dance and before you start dating, this is how you're scoping them out, right? You're making sure, hmm, will they be a good fit. Due diligence, this is where your vendor completes this the SIG questionnaire, and this is whether you determine if they have SOC2 or ISO certs, and then if a pen test is needed. Contracting is the big next path of this. Is this where you have your SLAs, your right to audit, and breach notifications are built into this? And we've talked about this routinely that if you are working with your contracting team, that is a really great first step. Bringing them on is the onboarding. Step four, this is where your minimum necessary access is provided and integration is reviewed and approved by security. This means that your IT folks just don't turn on a VPN and let them come in and go, hello, everybody, here's the front door. No, we don't do that. We we actually have a process to do that. Monitoring, this is where you have a continuous security ratings and periodic reassessments, tiered to the risk tier specifically. And then offboarding. When they all roll off, which they all do at some point in time, this is how you disconnect them from the mothership. Okay, so as they're connected in, how you disconnect the tentacles and then let them go on their way. This is where access is revoked, data is returned or destroyed, and integration is formally closed. So the exam will test you this. They have favorite trap here is skipping straight to the contracting without documenting the due diligence. So again, think about that. Hey, you just got this great vendor. Let's move them into contracting. No, you need to have a due diligence in place where you did a security assessment on them to determine are you a fit? Evidence review has to happen before access is provisioned, not after. You need to make sure that you don't just bring them on willy-nilly. Okay, so this is a really good flow chart of how this works. Okay, and then again, maybe change from different organization to organization, but I love how this kind of goes into play to tell you what should be the back and forth. Just like you're talking with somebody, I try to tell my children this, you're having a conversation, it's like tentus, tentus, not tentus, tennis. You then go and you serve, and then they hit it back to you. You serve, they hit it back to you. All of these things are back and forth, back and forth, back and forth. So, how does this work? The business owner, the inter or the internal stakeholder who wants to use a vendor has the engagement. Hey, this is cool. So, what they do then is they reach out to security or your GRC team and they then have an engagement request. Now, this is a due diligence function. This is verifies the vendor's claims, issues a risk tier and approval to your, they're the master gate. They're the gatekeeper that'll before allows anybody to come into the organization. They then send it back to the business owner. Business owner goes, hmm, do I like this? Do I not like this? Just because they approve it, maybe I have some follow-up or some feedback. They may go talk to the vendor and say, hmm, this isn't quite working. Once they feel comfortable, they then send it back to contracts and procurement and they send it to them and say, hey, this is the approval. This is where we need to have it. Contracts, are you good to go? Now, the security and the GRC team, if you look at this box, and if you're listening to this on audio, head on over to CISP Cyber Training. I'll have the video there. But realistically, the due diligence and the contracts and procurement team are all together. When I was in security, I focused a lot on talking to my contracts and procurement team. There's a lot of symbiotic relationship between them. The contracts and the procurement team will then send back the with approval to the business owner saying, Yep, we're good to go. Contracts good, all the red lines have been approved, life is good, let's move on. The business owner will then present the contract to the vendor, and the vendor then says, Okay, cool, I like that. And they sign it, you sign it, then access will be provisioned. That's an important part in all this. It's a dance, but it does take some time. If you want to bring on a vendor next week, this probably won't happen unless you're a very small shop. It takes time. And contracts is usually the one that really is the sticky wicket in a lot of it, because they want to look at the legal language to make sure that they're not giving away too much in the contract. So, what does the exam test? Notice due diligence approval never leaves security GRC relationship. Business owners only ever see the financial signed contract. That's the separation, is exactly why a rubber stamp vendor skipping GRC is such a common breach root cause. It goes right to them. It just if that's an important part. The security GRC team is an important part of any organization's TRPM, TPRM program. So here's some contractual controls that every vendor agreement needs. This is big. This is big bullets for you. So if you're building a TPRM program, take this nugget. These are huge nuggets. Breach notification timeline and how fast a vendor must tell you. See the Vimeo and Dot case study specifically. But you need to have them in there. It's written down that this, if they have a breach or incident within their organization, you have 24 to 72 hours. Now, I would also understand what they define a breach or an incident. That's an important language knowledge for you to know. What do they consider it? Do they consider it basically all of their data stolen as an incident? Or if there's a smaller, much smaller type of situation, does that fall under the incident category? A right to clause audit. This is a contractual right to assess and to send an auditor into the vendor's environment for high-tier vendors. Very important part, right to audit. So there's two things you take away from this is breach notification and right to audit clause. So continuous monitoring, how this works and the trade-offs behind it. So continuous monitoring works is the security ratings and platforms score vendors from their outside in without needing their cooperation. It flags new CVEs or leak credentials potentially that may be involved. I've had a Black Kite's a great company that helps with some more sort of monitoring around that. You can use security scorecard, bit site, or blackkite as well. You can also have SIG and questionnaire cycles, inside out, vendor reported, point-in-time aspects that are designed for your organization. But all of these things can be developed and set up within your company. Now, the monitoring trade-off is this is the high rating is not the same as a verified control. So someone may come in with an A plus rating, right? That doesn't mean the controls actually are there and in place. Now, if there was a bad thing that happened to them, real quickly they would go from an A plus to a C, a D, right? I've had dealt with a lot of vendors that had C's and D's. And then you have to ask yourself, is it somebody we really want to work with? Concentration

Frameworks Workflow And Monitoring

SPEAKER_01

risk, many customers depend on the same handful of shared vendors. So if you have a hand a vendor and they get compromised, how does that affect a lot of people? Because there's a lot of shared vendors in this space. Widely shared vendors become master keys. Attackers target them because of the connective tissue, not just because of the weakest link. They have all this sinew that is connected to everybody, and so therefore they are a huge target. Black Kype mentioned in 2026 70% of the top 50 shared vendors across Forbes Global 2000 carried a known exploit vulnerability. Yeah. So you need to make sure that as you're looking through this, it is an important part of any company's plan. You just TPRM is huge, but it just really gets overlooked. What is the exam test? Well, continuous monitoring closes the gap between the annual questionnaires and real-time exposure. The gap is exactly where the Vimeo and a dot breach did happen. So again, keep this in mind. Continuous monitoring closes the gap between an assessment and actual real-time exposure. It helps you have an understanding of what's going on. Okay, some TPRM frameworks and standards. It's important that you have knowledge around all seven of these. So we talked about 800-161 and ISO 27036, which we've mentioned, right? There's also the ones you need to be aware of of 27001 NXA, Cybersecurity Framework 2.0, SOC2, SIG, which we talked about at your shared standardized self-assessments, and then FAIR. FAIR is another one that I've talked about in previous episodes. But your factor analysis of information risk, that's FAIR. So these are standards and frameworks that it's important for you to be aware of. So, but notice the split, right? This is an exam quest or exam test aspect. 800-161, 2736, and CF 2.0 are program frameworks, how you run TPRM. SOC 2, SIG, and CIIQ are evidence standards, what the vendor gives you. And then FAIR is a risk quantification model. That is what the thing where this happens, where you're basically looking at the quantification related to vendor risk and putting a dollar figure on business impact. So the exam test will look at those potential aspects and may quiz you on that and question you on it. So third party and supply chain attack patterns. How are they doing this? Well, they do it through vendor credential compromise. Attackers will steal credentials issued to or by a vendor. They have standing access abuse, right? They will have attacker will ride a forgotten or still active vendor integration. Yes, that does happen, and I've seen it myself. Supply chain compromise, this is where malicious code is inserted, which we've mentioned before. Concentrated vendor compromise, this is where widely shared vendor breach cascades to hundreds of customers. Fourth party blind spots, MSP watering holes. Yes, they'll tack attack an MSP, a managed service provider, which then will then go cascade out from there. Extortion and leak site listing or silent disclosure delays. You can see all of this at CISSP Cyber Training. There's a whole just a slide on this specifically, so that you can go through and study for this for the exam. So some more exam traps at a glance. SOC 2 does not equal 27,001. SOC 2 is a US centric auditor attestation of specific controls over a period. 27001 is an international certification of an entire management system. Different scope, different rigor, often required together. However, they do get them used interchangeably. Most organizations may say, hey, if you're 27,001 certified, I don't, I could trust you, you're good, right? There's they use them interchangeably, but they are very different. SIG versus SIG Lite, the SIG is a full shared assessment questionnaire for higher risk vendors. Using a SIG Lite where a full SIG is warranted is a classic underscoping trap. Inherent risk versus residual risk. Inherent risk is the exposure before any controls are applied. How did you inherit that from the organization? Residual risk is what's left over after contractual and technical controls are in place. They're very different. So you need to understand the residual versus the inherent risk. And then third party risk versus supply chain risk. Those get used interchangeably as well. Third party risk covers your direct vendor relationships, your specific third parties. Supply chain covers the components, the code, the hardware of those vendors. That is the difference of it. So they're not the same. They are in some respects that the fact that the supply chain might be in their third party, or which it is of some sort of fashion, but third party and supply chain are not the same. Again, so just keep that in mind. Understand the differences between those. Notice the pattern across all four. The exam isn't testing whether you've memorized the acronyms, it's testing whether you can tell two similar sounding things apart in their scope and rigor. Okay, so here's some key acronyms for you to know. TPRM, we talked about third-party risk, C C Charlie, S C R M, which is your cyber supply chain risk, Dora, Digital Operational Resilience Act. DORA is an important thing for you to know, especially in the EU. SLA is service level agreements, RFPs, request for proposal. Kev is also known as a known exploited vulnerability. You have SBOM, which is your software bill of materials, very important part that you will deal with, especially if you're dealing with CMMC. All of these are some very important acronyms. There's more as well, but then you can see all of these at CISSP Cyber Training. So SIG versus SOC, SBOM versus CRM, and now Dora versus HeadRamp. These are separate categories covering self-attestation, independent evidence, and regulatory programs. Do not collapse them into one vendor paperwork buck bit. That's an important part. Okay, so let's get to some questions for you all. So we're gonna get into type one versus type two. So a tier one critical vendor sends a SOC 2 report stating the auditor has obtained an understanding of controls relevant to the trust services criteria, TSC, and determine that the controls were suitably designed. Okay, they're made, big $10 words. As of a single date three months ago, the vendor's onboarding paperwork calls this independent security verification. Does this satisfy the Tier 1 due diligence requirement? Okay, so you have a Tier 1 critical vendor and they seek to they send you a SOC 2 report stating the auditor obtained understanding of controls relevant to the trust services criteria. Okay, so this they did this three months ago. Does this satisfy your tier one due diligence requirement? A yes, a SOC 2 report is a SOC 2 report. The type doesn't matter for a Tier 1 vendor. B, yes, since a licensed CPA firm issued it, no further evidence is needed regardless of the vendor tier. C, no. This is a type one report describing design only at a point in time. A tier one vendor should require a type 2 evidence that controls operate effectively over a period. Or D, no. SOC 2 reports are never acceptable evidence for security reviews, regardless of the type. Okay, so what are we dealing with here? We're dealing with a tier one and we're dealing with a SOC 2 report stating the auditor, auditor, obtained an understanding of controls relevant to the trust services and determined that the controls were suitably designed. So obtained an understanding. Did they actually test the controls? So they didn't test the controls. So then it wouldn't be a type two, right? It would not be that at all. They looked at it as a type one. So the vendors on board of paperwork calls this as an independent security verification. They obtained an understanding they did not verify. So this is not true. So therefore, if it's not true, what it is is that SOC to type one. So then the answer would be C. Right. No, this is a type one report describing design only at a point in time. A tier one vendor should require type two evidence that requires controls operated effectively over a period. See, again, you're gonna have to watch this because this is a great test question, as well as it's also gonna be when you deal with third-party vendors. They say a lot of stuff in their marketing copy that is not totally true. And you have to call them out on this. You have to dig deeper and say, well, let me show me the controls. Wow, we don't have the controls. Well, then don't tell me that it was very independently security verified. That was not done. Okay, you gotta really dig deep in that. So again, no, correct is C, right? This type one attests do the controls were suitably designed for one date, date and time. The type two attests, those same controls operate effectively over a they review period, typically six to twelve months. So for a tier one critical vendor, the exam wants type two proof of sustained operation, not just a design snapshot. So again, this is a trap, is is that they mentioned a CPA firm. They mentioned the fact that they are doing a review. They said it is independently verified. All of these things do not change what the actual report was. So why were these wrong? So again, SOC 2 report is a SOC 2 report. Doesn't type doesn't matter. That is incorrect, right? This matters enormously. A type 1 confirms design only, type 2 confirms that the operation is in there over time. They're very, very important. Since the C B since the CPA firm issued it, no further evidence is needed. Oh great. So the CPA firm issued it, so they are the masters of the universe. No, they are not. They can issue a type one or type two, that's great, but it doesn't change the fact of what you're trying to look for. D SOC 2 reports never are acceptable evidence, regardless of type. Well, we all know that that's not true. Okay, they're an important part and they do could provide some level of evidence. You just need to decide which one is best for you and your organization. Okay, so let's get into fourth party risk by behavior, not buzzwords. Okay, so a healthcare company contract with its billing vendor requires SOC 2 type 2 evidence and an annual reassessment. 18 months later, the breach investigation realized that the billing vendor had quietly outsourced data processing to an offshore analytics firm. That was never ever disclosed, never assessed, and had no equivalent security requirements in its own contract.

Exam Practice Scenarios And Wrap Up

SPEAKER_01

Which control gap most directly is enables this? Okay, so what gap? Right? You got a healthcare company, they're with a building a billing vendor, and they require a SOC2 type 2 evidence and an initial reassessment. 18 months later, the breach investigation realized that the billing vendor had quietly, the third party, outsourced its data processing to an offshore analytics firm, fourth party that was never disclosed, never assessed, and had no equivalent security requirement of its own contract. So what what is the gap that most directly enabled this? A failure to require SOC2 type 2 evidence from the billing vendor. B, failure to include a subcontractor, fourth party disclosure, and a flow down requirement for the original contract. C, a failure to conduct an annual reassessment on schedule, or D, failure to encrypt data at rest while billing vendors own systems. Okay, so we what's a big problem here? The big problem here is that you require type two evidence in an annual reassessment. But the billing vendor just didn't tell you this, and they might do an assessment, but they didn't tell you that they outsourced their data processing to an offshore analytics firm. So who is that? That's fourth party, right? So we are dealing with you know that it's fourth party, then that you probably will bring you into the answer of B. Failure to include subcontractor, fourth party disclosure, again, fourth party, and flow down requirements. Flow down basically means, hey, does this go to them as well in the original contract? So your contract you had with a third party, did you have flow down requirements saying that yes? Whatever you do, if it goes to another party, they have to meet the same level of strictness and rigor that you have in yours. So let's kind of see if that's the right answer. Is it B?

SPEAKER_00

Oh yes, it's B.

SPEAKER_01

Yes, missing subcontractor disclose and flow down requirements. An important part, right? So, where's the trap in this? The scenario gives you a company that did several things right. SOC 2 type 2. Oh yay, and your reassessment. Oh yay. Specifically, so you don't default to blaming the obvious control. The actual gap is upstream in the contract, not the monitoring cadence. So, why are these other ones wrong? So let's go into B. Failure to require SOC 2 type 2 evidence. So SOC 2 type 2 evidence was obtained. That's not the gap in this scenario. It wasn't, it was gained, right? That was happened. But 18 months later, the hidden subcontractor got access. Not weak or missing vendor evidence, it was the subcontractor. B C, failure to conduct an annual reassessment on schedule. Timing isn't the root cause here. Even a reassessment conducting exactly on schedule wouldn't have caught this fourth party issued with their undisclosed subcontractor. If the contract never required disclosure in the first place, you wouldn't know it. And then D, failure to encrypt data at risk by the billing vendor. Encryption is a technical control unrelated to the disclosure failure described. So again, that they throw those in there just to go, oh, it needs encryption, and then they go down that path. Yeah, no, that's not the important part. The important part is the overall disclosure failure in this plan. Okay, so that's all I've got for you today at CISSP Cyber Training. I have a bunch of content for you, and it's available to you. Go check it out. Free stuff, lots of free stuff. There's also my sprint cohort, there's also the accelerator program and the probe program as well. Those are all available for you to get past the CISSP exam the first time. I'm excited about what's coming out of the future. I've got some great things coming out, but the cohort itself is just what's smoking. I truly want to keep bringing that home. The fact is that if you want to get your CISSP in the next eight weeks, the cohort is for you. Okay, thank you guys so much for joining me today, and we will catch you on the flip side. See ya. Thanks so much for joining me today on my podcast. If you like what you heard, please leave a review on iTunes as I would greatly appreciate your feedback. Also, check out my videos that are on YouTube, and just head to my channel at CISSP Cyber Training, and you will find a plethora or a conocopia of content to help you pass the CISSP exam the first time. Lastly, head to CISSP Cyber Training and sign up for 360 free CISSP questions to help you in your CISSP journey. Thanks again for listening.