TPRM-Driven Supply Chain Cybersecurity : Connecting TPRM and supply chain security for operational resilience

43.05 SGD
Member Price
38.75
English

Singapore Main Store

Available

F24-01 Floor (, )

Product Description

Integrate cybersecurity into TPRM to reduce vendor breach impact, meet DORA and NIST C-SCRM expectations, and monitor fourth-party exposure using SBOM-driven diligence, threat intelligence, and automation. Key Features Design a lifecycle-based TPRM program that ties vendor decisions to cyber risk Map DORA, NIST C-SCRM, and ISO/IEC 27036 controls to audits and evidence Build contract clauses, SBOM requirements, and playbooks for third- and fourth-party breaches Includes assessment templates, evidence checklists, and incident playbooks you can adapt Book DescriptionReduce supply chain cyber risk by turning third-party risk management into an operational program that connects procurement, legal, and security decisions. This book replaces checkbox assessments with a lifecycle approach you can apply from onboarding through offboarding, so vendor risk tiering, control mapping, and continuous monitoring drive clear outcomes. You learn how to align supplier oversight with major obligations and guidance, including DORA, GDPR, Executive Order 14028, NIST C-SCRM, and ISO/IEC 27036. You also get practical methods for strengthening contracts and SLAs—covering audit rights, breach notification, liability, and security requirements that flow down to critical subcontractors. From threat intelligence and security ratings to incident response playbooks for vendor and sub-vendor breaches, the book shows how to handle real signals, not just survey answers. Written by practitioners with deep experience in supply chain risk and offensive security, it also explains how SBOM standards and AI-assisted scoring can support scalable governance. By the end, you can build and mature an intelligence-driven TPRM program focused on measurable resilience.What you will learn Learn how vendor ecosystems become attack paths Categorize third- and fourth-party supply chain risks Create risk tiers and segmentation based on business impact Design a lifecycle workflow from onboarding to offboarding Select c

Integrate cybersecurity into TPRM to reduce vendor breach impact, meet DORA and NIST C-SCRM expectations, and monitor fourth-party exposure using SBOM-driven diligence, threat intelligence, and automation.

Key Features

Design TPRM lifecycle linking vendor risk to cyber -outcomes
Map NIST, ISO 27036, DORA, GDPR to audit-ready controls
Enforce contracts, SLAs, due diligence across 3rd/4th parties
Implement continuous monitoring beyond questionnaires
-Develop breach response playbooks with SBOM

Book DescriptionModern organizations rely on complex vendor ecosystems, but third-party risk management (TPRM) and cybersecurity often operate in silos. This book shows how to connect vendor risk management with supply chain cybersecurity using a practical, lifecycle-driven approach.
You'll design a program covering onboarding, vendor risk assessment, continuous monitoring, and offboarding. Instead of static questionnaires, you'll use threat intelligence, security ratings, and real-world signals to strengthen third-party security and improve decisions across procurement, legal, and security teams.
The book aligns practices with NIST supply chain risk management (C-SCRM), ISO 27036, DORA compliance, and GDPR, translating them into audit-ready controls and governance.
You'll learn how to embed vendor due diligence into contracts, manage fourth-party risk, and extend security requirements across suppliers. It also covers SBOM (Software Bill of Materials) standards such as SPDX and CycloneDX to improve software supply chain transparency.
Finally, you'll develop vendor breach response playbooks and apply automation and AI-driven risk scoring to scale your program. By the end, you can build a resilient, intelligence-led TPRM capability.What you will learn

Build a TPRM lifecycle for supply chain cybersecurity
Perform vendor risk assessment and tiering
Align with NIST C-SCRM, ISO 27036, and DORA
Embed vendor due diligence into contracts and SLAs
Identify and manage fourth-party risk exposure
Apply SBOM (SPDX, CycloneDX) to supplier security
Run vendor breach response for supply chain incidents
Use AI and automation to scale vendor risk management

Who this book is forThis book is for cybersecurity leaders, TPRM/VRM practitioners, risk managers, and procurement professionals who need a repeatable way to evaluate and monitor vendors and critical suppliers. Compliance teams and in-house counsel working with DORA, GDPR, HIPAA, and related requirements will also benefit. Basic familiarity with security principles and vendor management helps.

Available to Order

Usually dispatches within 3-5 business days

While every attempt has been made to ensure stock availability, occasionally we may run out of stock at our stores.

Free domestic shipping on orders over 50.00SGD

Discount is applied at checkout.

Recently Viewed Items

Related Products