Effective Security & Compliance Insights

Get practical, no-fluff advice for building a security program that wins deals and reduces risk.

Want practical security templates, checklists, and expert tips delivered to your inbox?

Filter by Tag

Stock photo by Erik Mclean via Pexels, illustrating vendor risk third party management (temporary placeholder pending custom hero design).

SOC 2 CC9.2: Vendor and Business Partner Risk Management

SOC 2 CC9.2 is the vendor and business partner risk criterion: it requires an organization to assess and manage the risks that come from the third...

Third-party risk management illustration showing a central security checklist and handshake shield connected to vendors, suppliers, service providers, customers, and partners, with security requirements and risk monitoring represented by supporting icons.

Third Party Risk Management (TPRM): What It Is and How to Build a Program

Third party risk management (TPRM) is the discipline of identifying, assessing, and controlling the risks that come from the external organizations a...

An illustration of a man reviewing a security risk register. Floating icons include a server rack, security badge door, user profile, microchip, and a vendor agreement. A calendar on his desk marks a review date, emphasizing an organized risk management process.

SOC 2 Risk Management for Hybrid and On-Prem Environments

TL;DR

  • Risk management maps to CC3.2 (risk identification and analysis), CC3.3 (fraud risk), and CC3.4 (changes that affect internal control)
  • On-prem...
An illustration titled "CPCSC Prime Contractor Direct Supply Chain Cybersecurity" showing a transition from "Old Ad Hoc Checks" (messy papers) to "Formal Documented SCRM." A person manages a structured supply chain network linked to a formal SCRM program with SA.1 and SA.2 security controls.

Supply Chain Risk Management Under CPCSC

For most of the history of Canadian defence procurement, cybersecurity obligations ended at the prime contractor's perimeter. A prime could hold a...