<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Third Party/Vendor Risk Assessment in Governance, Risk, Compliance</title>
    <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Third-Party-Vendor-Risk-Assessment/m-p/43413#M316</link>
    <description>I’ve had a good experience with Aptible. Their GRC product has a new 3rd party assessment tool that comes with some built-in questions or you can have them upload your own questionnaire (e.g. from Excel). It allows you to assign a risk rating to each question and then to the overall assessment. The assessment can then be tied to the vendor record in their vendor management module.</description>
    <pubDate>Thu, 18 Feb 2021 13:22:29 GMT</pubDate>
    <dc:creator>joeadu</dc:creator>
    <dc:date>2021-02-18T13:22:29Z</dc:date>
    <item>
      <title>Third Party/Vendor Risk Assessment</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Third-Party-Vendor-Risk-Assessment/m-p/43384#M307</link>
      <description>&lt;P&gt;We currently require our third parties to complete an Excel questionnaire as well as supply additional information for review.&amp;nbsp;&amp;nbsp; I'm researching vendors that have services online where third parties can complete questionnaires online and upload required information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Curious if anyone on here can recommend a service that is working out well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks much.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:48:10 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Third-Party-Vendor-Risk-Assessment/m-p/43384#M307</guid>
      <dc:creator>bspicer</dc:creator>
      <dc:date>2023-10-09T09:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: Third Party/Vendor Risk Assessment</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Third-Party-Vendor-Risk-Assessment/m-p/43389#M310</link>
      <description>Edit: I believe I misinterpreted your post with my original reply. My apologies!&lt;BR /&gt;&lt;BR /&gt;Knowbe4 has a GRC platform that can do that. It will send the questionnaire via email to the vendor and will auto save in the system when finished. It can even send on a predetermined schedule for convenience.</description>
      <pubDate>Thu, 18 Feb 2021 03:22:27 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Third-Party-Vendor-Risk-Assessment/m-p/43389#M310</guid>
      <dc:creator>tmekelburg1</dc:creator>
      <dc:date>2021-02-18T03:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: Third Party/Vendor Risk Assessment</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Third-Party-Vendor-Risk-Assessment/m-p/43400#M313</link>
      <description>&lt;P&gt;Excel saves the day again! We would not be able to do security assessments with out it&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 02:40:45 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Third-Party-Vendor-Risk-Assessment/m-p/43400#M313</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2021-02-18T02:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: Third Party/Vendor Risk Assessment</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Third-Party-Vendor-Risk-Assessment/m-p/43408#M315</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;We use a tool called Whistic to do our vendor risk assessments. Link - &lt;A href="https://www.whistic.com/" target="_blank"&gt;https://www.whistic.com/&lt;/A&gt;&lt;BR /&gt;They are not great but not bad either and they help reduce dependence on excel sheets by a lot.</description>
      <pubDate>Thu, 18 Feb 2021 11:15:43 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Third-Party-Vendor-Risk-Assessment/m-p/43408#M315</guid>
      <dc:creator>ArjitSrivastava</dc:creator>
      <dc:date>2021-02-18T11:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: Third Party/Vendor Risk Assessment</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Third-Party-Vendor-Risk-Assessment/m-p/43413#M316</link>
      <description>I’ve had a good experience with Aptible. Their GRC product has a new 3rd party assessment tool that comes with some built-in questions or you can have them upload your own questionnaire (e.g. from Excel). It allows you to assign a risk rating to each question and then to the overall assessment. The assessment can then be tied to the vendor record in their vendor management module.</description>
      <pubDate>Thu, 18 Feb 2021 13:22:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Third-Party-Vendor-Risk-Assessment/m-p/43413#M316</guid>
      <dc:creator>joeadu</dc:creator>
      <dc:date>2021-02-18T13:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: Third Party/Vendor Risk Assessment</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Third-Party-Vendor-Risk-Assessment/m-p/43432#M320</link>
      <description>&lt;P&gt;The benefits of an Excel spreadsheet are undeniable.&amp;nbsp; Security Scorecard's Atlas allows you to leverage ratings while tracking the questionnaire responses.&amp;nbsp; Presenting benefits that outweigh the spend added to being able to automate the overall process may help to convince executive management.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2021 03:49:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Third-Party-Vendor-Risk-Assessment/m-p/43432#M320</guid>
      <dc:creator>canLG0501</dc:creator>
      <dc:date>2021-02-19T03:49:40Z</dc:date>
    </item>
  </channel>
</rss>

