Related Posts
There is coin for it!
Thought's on Speedy FOIS?
Additional Posts in Cyber Security Bowl
Does formatting destroy data on a HDD?
Any insight on the culture of InfoSec at Hulu?
Symantec DLP or Digital Guardian and why?
New to Fishbowl?
Download the Fishbowl app to
unlock all discussions on Fishbowl.
unlock all discussions on Fishbowl.
Managing the cyber risk of all third party vendors, suppliers, relationships. Performing assessments, tiering risk of findings in networks of all third parties, monitoring those relationships, sourcing and contracting out new vendors and suppliers for the enterprise
TPRM goes beyond IT
Managing risks related to vendors, contractors, suppliers, service providers, etc. It can be any vendor not just a vendor that provides IT services
TPRM isn’t just aligned to IT it’s ALL vendors an organization is dealing with
Assessing your vendors, identifying the risks that come up with hiring a third part vendor/supplier. Assessing what kind of access they have etc. etc.
This all also ties back to BCP/DR
How does the compensation in TPRM look like?
Yeah so TPRM in industry would be boring, but TPRM consulting is better - it is more strategy than audit.
Similarly for comp: great in consulting, probably less so in industry
Here what it means in FSI. Cyber TPRM is just a small part of the TPRM owned by procurement.
https://www.occ.gov/news-issuances/bulletins/2013/bulletin-2013-29.html
Think of the application of enterprise risk management outside the confines of your organization
The bane of my existence
At EY they have TPRM business consulting and also within cyber tech consulting they have a capability that covers TPRM. So there is some overlap there. Honestly it is all questionnaire and generating reports. Inbox me if you have more questions or want ideas on how to get involved.
What can one do when they leave TPRM for industry?
Wow.