Module 5 · Third-Party and Supply-Chain Risk Management

Manish Garg
Manish Garg Associate of (ISC)² · RingSafe
May 14, 2026
4 min read
Read as
100% Free

No signup. No paywall. No catch. One of our 10 most-requested practitioner modules — published in full so anyone can learn for free. We earn through consulting, not by gating knowledge.

See all 10 free modules →

Why this module exists. Third-party and supply-chain risk is the single fastest-growing risk category in Indian enterprises. SolarWinds, Log4j, Okta, MOVEit, XZ Utils — every major breach pattern of the last five years has involved a trusted third party. This module covers the practical assessment framework: tiering vendors by risk, the right questionnaire depth, evidence collection, and continuous monitoring.

Why this module exists. The threat model has shifted. The hardest perimeter to defend now is your vendors’ perimeter. This module is the practitioner programme: how to tier, assess, monitor, and respond.

The tiering — start here

Not every vendor needs the same scrutiny. Categorise based on data sensitivity, access level, and operational dependency:

Tier Examples Assessment depth
Tier 1 — Critical Cloud (AWS, Azure), Payment processor, KMS provider, Core banking platform SOC 2 Type II + on-site / virtual audit annually + contractual right to audit
Tier 2 — High HR platform with PII access, identity provider, MDM, SIEM SOC 2 Type II review + questionnaire + reference checks
Tier 3 — Medium Marketing automation, analytics, CRM Self-attestation questionnaire + public security posture review
Tier 4 — Low Office supplies, travel booking, generic SaaS Standard procurement clauses only

The questionnaire problem

Most Indian-enterprise vendor questionnaires are 200+ questions of compliance theatre. Vendors copy-paste answers from the last one. The information value is near zero.

The right approach: SIG (Standardised Information Gathering) or CAIQ (Consensus Assessments Initiative Questionnaire) as the standard format. Vendors who have completed these for other customers can share once. You combine with evidence collection:

  • Most recent SOC 2 Type II report (the report, not just the certificate).
  • Most recent independent penetration test summary.
  • Most recent ISO 27001 surveillance audit report.
  • Breach disclosure history — anything in the last 24 months.
  • Subprocessor list and the certifications they hold.

The questionnaire answers fill in the gaps the documents do not cover. The documents are evidence; the questionnaire is interpretation.

The contract — clauses that matter

  • Breach notification timeline. 24 hours of vendor’s becoming aware. Tighter than DPDP 72h to give you headroom for your own regulatory clock.
  • Right to audit. Especially for Tier 1. Quarterly virtual; annual on-site.
  • Subprocessor consent. Vendor must notify before adding a new subprocessor; you retain right to object.
  • Data location and residency. Where your data is stored, with notification before any change. DPDP Phase 2 makes this auditable.
  • Data deletion / return on termination. Verifiable proof of deletion, not just an attestation.
  • Liability cap. Sufficient relative to the data sensitivity. ₹2 Cr cap on a vendor processing 4M customer records is insufficient.
  • Cyber-insurance evidence. Vendor provides annual proof of cyber coverage at appropriate limits.

Continuous monitoring — what to watch after onboarding

  • BitSight / SecurityScorecard / RiskRecon: external attack-surface ratings. Useful for Tier 1-2; cost £/$ scales fast.
  • Have I Been Pwned domain monitoring: alert when employees of a critical vendor appear in breach corpora.
  • Public-facing CVE feed: subscribe to vendor’s security advisory channel. RSS, email, security.txt.
  • SOC integration: critical vendors should provide a security data feed or, at minimum, periodic threat-intel briefings.
  • Annual reassessment: re-run the questionnaire and evidence collection annually for Tier 1-2; biennial for Tier 3.

Supply-chain attack scenarios — what to specifically defend against

  1. Compromised software update (SolarWinds pattern). Defender: code-signing verification on updates; staged rollout with monitoring before fleet-wide.
  2. Compromised dependency (Log4j, XZ pattern). Defender: SBOM tracking, dependency-pinning, scanning for known-vulnerable transitives.
  3. Compromised SaaS vendor (Okta pattern). Defender: tier-1 vendor controls; minimise blast radius via least-privilege OAuth scopes.
  4. Compromised hardware (TigerJet, rare but exists). Defender: source from supply-chain-attested vendors for sensitive deployments.

The Indian-regulatory overlay

  • DPDP Rules: data processor contracts mandatory; data fiduciary remains responsible for processor breaches.
  • RBI Cyber Security Framework: explicit third-party risk management requirements; ESC vendor due diligence is regulator-inspected.
  • RBI IT Outsourcing Master Direction: prescribes a 12-element due-diligence process for IT outsourcing vendors; mandatory exit plan for critical services.
  • SEBI CSCRF: third-party security as a named control domain.

Onboarding — the rapid-assessment pattern

Procurement teams want vendor onboarding in weeks, not months. The pattern that works:

  1. Tier the vendor in week 1 based on data + access + criticality.
  2. Tier 4: standard procurement clauses; no further security review.
  3. Tier 3: 30-question self-attestation completed by vendor; security review <2 days.
  4. Tier 2: SOC 2 Type II review + condensed questionnaire; 1-2 weeks.
  5. Tier 1: full assessment; 3-6 weeks; security veto if findings unacceptable.

Make the timeline visible to procurement so they plan accordingly.

Key takeaways

  • Tier vendors 1-4 by data sensitivity, access level, operational dependency.
  • Evidence first (SOC 2, pentest, breach history); questionnaire fills gaps.
  • Contract clauses: notification, right to audit, subprocessor consent, residency, deletion, liability cap, insurance.
  • Continuous monitoring: external rating service for Tier 1-2; annual reassessment.
  • Defend against four supply-chain attack patterns: software update, dependency, SaaS, hardware.
  • India regulatory: DPDP processor contracts, RBI IT Outsourcing, SEBI CSCRF.
DPDP Act in your stack?

Get a DPDP gap assessment

Free 30-minute call. We map your data flows against DPDP §8 obligations and tell you exactly which gaps to fix first. Auditor-defensible output.

Book DPDP scoping call Replies in 4 working hrs · India-only · Senior consultants